Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

York School District One details PowerSchool data-breach response; few active students affected, district says

York School District One Board of Trustees · January 14, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The district's technology director told trustees a global PowerSchool breach accessed hosted data, including some personal information; preliminary district checks indicate no active students affected and four active employees possibly impacted. The vendor and state are leading notification and remediation.

York School District One technology officials updated the board on a PowerSchool cybersecurity incident that affected hosted customer instances, saying the vendor alerted districts on Jan. 7 after a threat actor used a compromised support account to access data.

"We were alerted at that time that our data was accessed," Director of Technology Chuck Wallace told trustees, outlining a timeline in which a stale account was used to probe systems Dec. 19'21, scripts were used to exfiltrate data on Dec. 23 and PowerSchool learned of the intrusion Dec. 28. Wallace said the vendor contracted cybersecurity firm CrowdStrike, disabled the compromised account and required password resets for remote-access accounts.

Wallace said the district's preliminary review found personally identifiable information (PII) in the fields accessed, including names, phone numbers, street addresses and, in some cases, Social Security numbers. He said the district currently believes there are zero active students affected and four active employees whose information was accessed; district staff said they are continuing a careful verification with the state and PowerSchool before issuing broader notifications.

"This was not on us at all," Wallace said, stressing that PowerSchool reported the incident and that the vendor is responsible for notifications and any credit-monitoring required by law. He described PowerSchool's use of outside investigators and monitoring of dark-web activity as part of remediation.

District staff said they removed stored Social Security numbers that were not required and disabled an integration that was writing to those fields. They also said they will run monthly and quarterly checks to ensure no Social Security numbers are reintroduced into PowerSchool fields going forward.

Trustees thanked technology staff and state partners for their rapid coordination. The district said it has reported the incident to the South Carolina state cybersecurity authorities and will notify affected individuals after confirmation with PowerSchool and state guidance. PowerSchool's detailed incident reports that the district is awaiting were expected from the vendor on or around Jan. 17, district staff said.

Next steps include continued forensic review with CrowdStrike, coordination with state cyber-response teams and individualized notification to any confirmed affected persons, in accordance with legal requirements.