Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
District IT director flags possible PowerSchool intrusion; parents to be notified if data affected
Summary
RSU 73 IT director reported anomalies in PowerSchool logs after a statewide cyberattack on the student-information vendor; the district has opened a case with PowerSchool and said contact information and some attachments (IEPs, medical notes) could be present in the system but that Social Security numbers are not stored locally.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Chris, RSU 73's IT director, told the school board that PowerSchool — a widely used student information system — was the target of a statewide cyberattack and that the district has opened a case with the vendor after finding log entries that "didn't look quite right." "We don't have anything in there like Social Security numbers or anything like that," Chris said, adding that PowerSchool stores contact information and some student-related attachments.
Chris described the next step as sharing the district's log files with PowerSchool for a deeper review. "If for some reason they said that they were wrong and it did look like somebody might have got into our system, then we can let parents know," he said, urging transparency pending vendor confirmation.
Board members pressed for details about what could be exposed. When asked whether IEPs or medical information were accessible, Chris said some individual plans and medical records live in PowerSchool as attachments and "that would be a little more difficult to pull up because it's in an attachment," but emphasized attachments still exist in the system. He said the district's recent move to cloud-based services reduces exposure of locally hosted servers but does not eliminate the risk tied to a vendor's platform.
On liability, Chris told the board that responsibility would likely lie with PowerSchool because the vendor's servers were targeted, but he said the district would take responsibility for notifying affected families if an intrusion impacting RSU 73 is confirmed. The district has not concluded whether any data was exfiltrated and said the investigation is ongoing.

