Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Weare School District says PowerSchool data portal was accessed; district offers monitoring and is coordinating response

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

SAU 24 staff said a malicious actor accessed data through the PowerSource portal at PowerSchool. The district reported no operational disruption to school functions, has notified families, filed an insurance claim, and is coordinating law‑enforcement and vendor remediation.

The Weare School District notified families after PowerSchool — the student information system used by the district — disclosed that a malicious actor gained unauthorized access to certain information via PowerSchool’s PowerSource portal.

Lee, the district’s IT representative, told the board the incident was disclosed to the district on Jan. 7 by PowerSchool. PowerSchool advised the district that the incident affected some hosted and non‑hosted clients via that portal; the district said the incident did not disrupt daily school operations or systems used for attendance and grades.

PowerSchool informed districts it believed a malicious actor deleted the stolen data after access and that the attack was financially motivated; the vendor reportedly paid a sum intended to prevent public release of the stolen data. PowerSchool has offered credit monitoring to impacted adults and identity‑protection services for minors consistent with regulatory and contractual obligations, the district said.

District officials said they filed a claim with the district’s cyber insurance carrier, attended vendor briefings on PowerSchool’s response, notified law enforcement and regulators and have communicated an initial notice to teachers and families. The district said it will provide further updates as the vendor and insurance provider deliver additional details.

District staff emphasized that the incident was targeted at the vendor and not an SAU system compromise; the district said it is following its cybersecurity incident‑response plan and coordinating with partners to mitigate risk.

Ending: Officials said they will continue to update the board and families as more information becomes available and encouraged guardians with specific concerns to contact the district for guidance on the protective services being offered.