Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Breach topic

No spam. Unsubscribe anytime.

RSU 26 officials say PowerSchool breach exposed student and staff records; district seeks detail from vendor

RSU 26 School Board · January 21, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The superintendent told the RSU 26 board a vendor'side breach of PowerSchool accessed student and staff tables, including some medical alerts and about 10% of student Social Security numbers; PowerSchool will send individualized notices and two years of credit monitoring for affected adults, officials said.

The RSU 26 superintendent told the school board that a recent vendor-side breach of the PowerSchool student information system accessed the district'wide student and staff tables, and that the vendor is handling required notifications.

"PowerSchool is the vendor that caused this breach," the superintendent said, and staff were able to review logs to confirm the access window and username. The superintendent said the breach occurred through PowerSchool's service portal, which allows vendor maintenance access when an open ticket exists.

Board members pressed for specifics about what fields were exposed. The superintendent said the stolen data included the student table and staff table contents, noting that "we do not keep our HR information in PowerSchool" and that staff entries are limited to billing name, email address and phone number. For students, required demographic and program fields and some special fields — including medical alerts and, in about 10% of cases, Social Security numbers — were present in the dataset taken.

The superintendent told the board that PowerSchool had said it will "send out individualized notifications to impacted individuals" and is providing two years of identity-theft protection and credit monitoring for adults whose information was affected. The district's cyber insurer recommended coordinating with PowerSchool's planned notifications and seeking a copy of PowerSchool's forensic investigative report; the superintendent said the district will request that report and, if necessary, use insurer-provided legal resources to review notification obligations.

Board members also raised concerns that exposed email addresses and phone numbers could increase phishing and scam risk for students and staff. The superintendent said the district would consider targeted communications and schooling on credit monitoring enrollment and phishing awareness, and evaluate whether a security audit of other systems is warranted.

The superintendent provided counts to the board: "We had 1,786 students in the system" and "we had 599 staff members in the system," and said the exact composition of fields varies by district. The board asked the superintendent to continue pushing PowerSchool for more detailed information and to report back on the forensic findings and the vendor'led notification outcomes.

Next steps: the district will seek PowerSchool's forensic report, coordinate notification and monitoring rollouts, consult cyber-insurance attorneys if needed, and evaluate additional internal security and communication measures.