mastouille.fr est l'un des nombreux serveurs Mastodon indépendants que vous pouvez utiliser pour participer au fédiverse.
Mastouille est une instance Mastodon durable, ouverte, et hébergée en France.

Administré par :

Statistiques du serveur :

597
comptes actifs

#powerschool

0 message0 participant0 message aujourd’hui
Dissent Doe :cupofcoffee:<p>Breaches have consequences (sometimes):</p><p>"On Monday, the North Carolina State Board of Education approved a six-month, roughly $270,000 contract with PowerSchool for professional evaluations and onboarding services. The contract, NCDPI noted, isn’t related to the student information system, which was hacked in December. That system’s contract will expire at the end of June and won’t be renewed."</p><p><a href="https://www.wect.com/2025/06/25/ncdpi-renews-contract-with-powerschool-after-massive-data-breach/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">wect.com/2025/06/25/ncdpi-rene</span><span class="invisible">ws-contract-with-powerschool-after-massive-data-breach/</span></a></p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a> <a href="https://infosec.exchange/tags/EduSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EduSec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> </p><p><span class="h-card" translate="no"><a href="https://infosec.exchange/@douglevin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>douglevin</span></a></span> <span class="h-card" translate="no"><a href="https://freeradical.zone/@funnymonkey" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>funnymonkey</span></a></span> <span class="h-card" translate="no"><a href="https://journa.host/@mkeierleber" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>mkeierleber</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@brett" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>brett</span></a></span></p>
Dissent Doe :cupofcoffee:<p>Attribution is hard, Thursday edition...</p><p>NEW by me: A guilty plea in the PowerSchool case still leaves unanswered questions</p><p><a href="https://databreaches.net/2025/06/12/a-guilty-plea-in-the-powerschool-case-still-leaves-unanswered-questions/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2025/06/12/a-</span><span class="invisible">guilty-plea-in-the-powerschool-case-still-leaves-unanswered-questions/</span></a></p><p><a href="https://infosec.exchange/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a> <a href="https://infosec.exchange/tags/hack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hack</span></a> <a href="https://infosec.exchange/tags/extortion" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>extortion</span></a> <a href="https://infosec.exchange/tags/attribution" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>attribution</span></a> <a href="https://infosec.exchange/tags/transparency" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>transparency</span></a> <a href="https://infosec.exchange/tags/incidentresponse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>incidentresponse</span></a> </p><p><span class="h-card" translate="no"><a href="https://infosec.exchange/@douglevin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>douglevin</span></a></span> <span class="h-card" translate="no"><a href="https://freeradical.zone/@funnymonkey" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>funnymonkey</span></a></span> <span class="h-card" translate="no"><a href="https://journa.host/@mkeierleber" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>mkeierleber</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@brett" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>brett</span></a></span></p>
Dissent Doe :cupofcoffee:<p>Help, please:</p><p>If anyone has a copy of the ransom note sent to PowerSchool in December 2024 or PowerSchool clients in May 2025, please email me a copy or upload it to me on Signal. I want to see not only the body, but the full header and signature. </p><p>PowerSchool has not been transparent about the extortion aspects of the incident and has not responded to inquiries.</p><p>To reach me on Signal, my number is +1 516-776-7756. Email: breaches@databreaches[.]net </p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/extortion" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>extortion</span></a> <a href="https://infosec.exchange/tags/ransom" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransom</span></a> <a href="https://infosec.exchange/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a> </p><p><span class="h-card" translate="no"><a href="https://infosec.exchange/@douglevin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>douglevin</span></a></span> <span class="h-card" translate="no"><a href="https://freeradical.zone/@funnymonkey" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>funnymonkey</span></a></span> <span class="h-card" translate="no"><a href="https://journa.host/@mkeierleber" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>mkeierleber</span></a></span></p>
The New Oil<p><a href="https://mastodon.thenewoil.org/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a> hacker pleads guilty to student data extortion scheme</p><p><a href="https://www.bleepingcomputer.com/news/security/powerschool-hacker-pleads-guilty-to-student-data-extortion-scheme/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/powerschool-hacker-pleads-guilty-to-student-data-extortion-scheme/</span></a></p><p><a href="https://mastodon.thenewoil.org/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a> <a href="https://mastodon.thenewoil.org/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://mastodon.thenewoil.org/tags/education" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>education</span></a> <a href="https://mastodon.thenewoil.org/tags/DataBreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataBreach</span></a> <a href="https://mastodon.thenewoil.org/tags/cybercrime" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybercrime</span></a></p>
Dissent Doe :cupofcoffee:<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@FritzAdalis" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>FritzAdalis</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@scottwilson" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>scottwilson</span></a></span> </p><p>That's not accurate. The Information's wording and organization may have confused people. </p><p>Para 5 in the Information is about Employee 1, a contractor who worked for PowerSchool. The Information does not say Employee 1 was a telco (Victim 1) employee or that their PS credentials were acquired as part of the telco breach. Para 5 is unrelated to Para 4. </p><p>The Employee 1 creds used to access PowerSchool were acquired at a separate time and unrelated to the telco breach. I confirmed that with a source with knowledge of the incident. </p><p>The Information: <a href="https://www.justice.gov/usao-ma/media/1400921/dl" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">justice.gov/usao-ma/media/1400</span><span class="invisible">921/dl</span></a></p><p>Also of note: the Information makes no mention of the second round of extortion attempts, which may mean that DOJ had no evidence connecting Lane to the second set of extortion demands. The second round of extortion demands purported to be from "ShinyHunters," but whether they really were or not has yet to be publicly confirmed or refuted by law enforcement. </p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/EduSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EduSec</span></a> <a href="https://infosec.exchange/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a> </p><p><span class="h-card" translate="no"><a href="https://infosec.exchange/@douglevin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>douglevin</span></a></span> <span class="h-card" translate="no"><a href="https://freeradical.zone/@funnymonkey" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>funnymonkey</span></a></span> <span class="h-card" translate="no"><a href="https://journa.host/@mkeierleber" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>mkeierleber</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@campuscodi" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>campuscodi</span></a></span></p>
Dissent Doe :cupofcoffee:<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@scottwilson" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>scottwilson</span></a></span> I had the same reaction. I even emailed the Media contact for the Massachusetts USAO to ask why the information included <em>enhanced</em> sentences for use of "special skills" and use of "sophisticated means" under USSG § 3Bl.3 and USSG § 2B 1.1(b )(1 0)(C)), respectively.</p><p>What "special skills?"</p><p>What "sophisticated means?"</p><p>I suspect they won't really answer me, but... I had to ask. </p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a> <a href="https://infosec.exchange/tags/EduSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EduSec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a></p><p>UPDATING: The USAMA responded:</p><p>"The only information we can provide is that publicly available in the court filings - which are linked in the press release. Apart from that we have no comment. Thank you.&nbsp;"</p><p>Someone find me a good "shocked look" emoji, please.</p>
Dissent Doe :cupofcoffee:<p>Massachusetts hacker to plead guilty to PowerSchool data breach:</p><p><a href="https://www.investing.com/news/stock-market-news/massachusetts-hacker-to-plead-guilty-to-powerschool-data-breach-4055643" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">investing.com/news/stock-marke</span><span class="invisible">t-news/massachusetts-hacker-to-plead-guilty-to-powerschool-data-breach-4055643</span></a></p><p>Related: </p><p>DOJ Press release: <a href="https://www.justice.gov/usao-ma/pr/worcester-college-student-plead-guilty-cyber-extortions" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">justice.gov/usao-ma/pr/worcest</span><span class="invisible">er-college-student-plead-guilty-cyber-extortions</span></a></p><p>USA v. Matthew D. Lane - Information: <a href="https://www.justice.gov/usao-ma/media/1400921/dl" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">justice.gov/usao-ma/media/1400</span><span class="invisible">921/dl</span></a></p><p>USA v. Matthew D. Lane - Plea Agreement: <br><a href="https://www.justice.gov/usao-ma/media/1400926/dl" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">justice.gov/usao-ma/media/1400</span><span class="invisible">926/dl</span></a></p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a> <a href="https://infosec.exchange/tags/EduSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EduSec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> </p><p><span class="h-card" translate="no"><a href="https://infosec.exchange/@douglevin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>douglevin</span></a></span> <span class="h-card" translate="no"><a href="https://freeradical.zone/@funnymonkey" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>funnymonkey</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@brett" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>brett</span></a></span> <span class="h-card" translate="no"><a href="https://journa.host/@mkeierleber" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>mkeierleber</span></a></span></p>
Doug Levin<p>Some useful advice here: PowerSchool Data Breach Developments <a href="https://www.edtechirl.com/p/powerschool-data-breach-developments" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">edtechirl.com/p/powerschool-da</span><span class="invisible">ta-breach-developments</span></a> <a href="https://infosec.exchange/tags/edtech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>edtech</span></a> <a href="https://infosec.exchange/tags/edusec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>edusec</span></a> <a href="https://infosec.exchange/tags/powerschool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>powerschool</span></a> <span class="h-card" translate="no"><a href="https://infosec.exchange/@PogoWasRight" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>PogoWasRight</span></a></span> <span class="h-card" translate="no"><a href="https://freeradical.zone/@funnymonkey" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>funnymonkey</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@brett" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>brett</span></a></span></p>
The New Oil<p><a href="https://mastodon.thenewoil.org/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a> hacker now extorting individual school districts</p><p><a href="https://www.bleepingcomputer.com/news/security/powerschool-hacker-now-extorting-individual-school-districts/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/powerschool-hacker-now-extorting-individual-school-districts/</span></a></p><p><a href="https://mastodon.thenewoil.org/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a> <a href="https://mastodon.thenewoil.org/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://mastodon.thenewoil.org/tags/education" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>education</span></a></p>
deltatux :donor:<p><span>PowerSchool, the cloud platform provider providing services to school boards across Canada &amp; the US has confirmed that even though a ransom has been paid to the cybercriminals holding the data ransom &amp; received assurances that the data was destroyed, the criminals have returned demanding for more money as they have not actually destroyed the data.<br><br>This unfortunately highlights the biggest risk when it comes to paying ransom for data destruction, threat actors can always come back demanding for more once they realize exactly how valuable the data is.<br><br></span><a href="https://www.thestar.com/news/gta/student-data-obtained-in-a-cyberattack-on-gta-school-boards-was-supposed-to-be-destroyed/article_cf2901bb-3fcc-4f84-ad7b-32399076b7e5.html" rel="nofollow noopener noreferrer" target="_blank">www.thestar.com/news/gta/student-data-obtained-in-a-cyberattack-on-gta-school-boards-was-supposed-to-be-destroyed/article_cf2901bb-3fcc-4f84-ad7b-32399076b7e5.html</a><span><br><br></span><a href="https://infosec.town/tags/infosec" rel="nofollow noopener noreferrer" target="_blank">#infosec</a><span> </span><a href="https://infosec.town/tags/PowerSchool" rel="nofollow noopener noreferrer" target="_blank">#PowerSchool</a><span> </span><a href="https://infosec.town/tags/PowerSchoolHack" rel="nofollow noopener noreferrer" target="_blank">#PowerSchoolHack</a><span> </span><a href="https://infosec.town/tags/ransom" rel="nofollow noopener noreferrer" target="_blank">#ransom</a><span> </span><a href="https://infosec.town/tags/TDSB" rel="nofollow noopener noreferrer" target="_blank">#TDSB</a><span> </span><a href="https://infosec.town/tags/YRDSB" rel="nofollow noopener noreferrer" target="_blank">#YRDSB</a><span> </span><a href="https://infosec.town/tags/PDSB" rel="nofollow noopener noreferrer" target="_blank">#PDSB</a><span> </span><a href="https://infosec.town/tags/Toronto" rel="nofollow noopener noreferrer" target="_blank">#Toronto</a><span> </span><a href="https://infosec.town/tags/YorkRegion" rel="nofollow noopener noreferrer" target="_blank">#YorkRegion</a><span> </span><a href="https://infosec.town/tags/PeelRegion" rel="nofollow noopener noreferrer" target="_blank">#PeelRegion</a><span> </span><a href="https://infosec.town/tags/Ontario" rel="nofollow noopener noreferrer" target="_blank">#Ontario</a><span> </span><a href="https://infosec.town/tags/Canada" rel="nofollow noopener noreferrer" target="_blank">#Canada</a></p>
Dissent Doe :cupofcoffee:<p>Today's reminder why NOT to pay criminals' extortion demands to delete data:</p><p>PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway</p><p><a href="https://databreaches.net/2025/05/07/powerschool-paid-a-hackers-extortion-demand-but-now-school-district-clients-are-being-extorted-anyway/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2025/05/07/po</span><span class="invisible">werschool-paid-a-hackers-extortion-demand-but-now-school-district-clients-are-being-extorted-anyway/</span></a></p><p>NOTE: I subsequently edited my post to clarify that the ransom demand to the state (North Carolina) claimed to be from ShinyHunters. I haven't yet seen any ransom notes to individual districts and I do not know how those were signed or claimed. Stay tuned, I guess....</p><p><a href="https://infosec.exchange/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a> <a href="https://infosec.exchange/tags/hack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hack</span></a> <a href="https://infosec.exchange/tags/EduSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EduSec</span></a> <a href="https://infosec.exchange/tags/EdTech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EdTech</span></a> <a href="https://infosec.exchange/tags/extortion" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>extortion</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> </p><p><span class="h-card" translate="no"><a href="https://infosec.exchange/@douglevin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>douglevin</span></a></span> <span class="h-card" translate="no"><a href="https://freeradical.zone/@funnymonkey" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>funnymonkey</span></a></span> <span class="h-card" translate="no"><a href="https://journa.host/@mkeierleber" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>mkeierleber</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@brett" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>brett</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@euroinfosec" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>euroinfosec</span></a></span> <span class="h-card" translate="no"><a href="https://ioc.exchange/@jgreig" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>jgreig</span></a></span></p>
whoosh<p><span class="h-card" translate="no"><a href="https://mastodon.social/@zackwhittaker" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>zackwhittaker</span></a></span> </p><p>Thanks to TechCrunch for this fine synopsis, and for keeping this issue in the light.</p><p><a href="https://social.sdf.org/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a></p>
Europe Says<p><a href="https://www.europesays.com/1809932/" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="">europesays.com/1809932/</span><span class="invisible"></span></a> Rochester schools’ data breach exposes over 130,000 student records <a href="https://pubeurope.com/tags/cyberattack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cyberattack</span></a> <a href="https://pubeurope.com/tags/Data" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Data</span></a> <a href="https://pubeurope.com/tags/DataBreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataBreach</span></a> <a href="https://pubeurope.com/tags/Dr" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Dr</span></a>.DemarioStrickland <a href="https://pubeurope.com/tags/IdentityTheft" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IdentityTheft</span></a> <a href="https://pubeurope.com/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a> <a href="https://pubeurope.com/tags/rochester" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>rochester</span></a> <a href="https://pubeurope.com/tags/SchoolDistrict" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SchoolDistrict</span></a> <a href="https://pubeurope.com/tags/StudentRecords" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>StudentRecords</span></a></p>
Anonymous 🐈️🐾☕🍵🏴🇵🇸 :af:<p>Education software giant <a href="https://kolektiva.social/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a> has started notifying individuals in the U.S. and Canada whose personal data was exposed in a late December 2024 cyberattack. <a href="https://kolektiva.social/tags/CyberAlerts" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberAlerts</span></a> <a href="https://kolektiva.social/tags/CyberAttacks" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberAttacks</span></a> <a href="https://kolektiva.social/tags/DataBreaches" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataBreaches</span></a> </p><p><a href="https://www.bleepingcomputer.com/news/security/powerschool-starts-notifying-victims-of-massive-data-breach/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/powerschool-starts-notifying-victims-of-massive-data-breach/</span></a></p>
Dissent Doe :cupofcoffee:<p>Rochester NY had 134,000 students and an unspecified number of staff members affected by the <a href="https://infosec.exchange/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a>. Here's their breach page: </p><p><a href="https://www.rcsdk12.org/databreach" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">rcsdk12.org/databreach</span><span class="invisible"></span></a></p><p>I'm not sure if this is the first that they are posting anything or alerting anyone. </p><p><span class="h-card" translate="no"><a href="https://infosec.exchange/@douglevin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>douglevin</span></a></span> <span class="h-card" translate="no"><a href="https://freeradical.zone/@funnymonkey" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>funnymonkey</span></a></span></p>
gtbarry<p>PowerSchool hacker claims they stole data of 62 million students</p><p>The hacker who breached education tech giant PowerSchool claimed in an extortion demand that they stole the personal data of 62.4 million students and 9.5 million teachers.</p><p><a href="https://mastodon.social/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a> <a href="https://mastodon.social/tags/education" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>education</span></a> <a href="https://mastodon.social/tags/edtech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>edtech</span></a> <a href="https://mastodon.social/tags/cyberattack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cyberattack</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://mastodon.social/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://mastodon.social/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://mastodon.social/tags/hackers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hackers</span></a> <a href="https://mastodon.social/tags/hacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacking</span></a> <a href="https://mastodon.social/tags/hacked" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacked</span></a></p><p><a href="https://www.bleepingcomputer.com/news/security/powerschool-hacker-claims-they-stole-data-of-62-million-students/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/powerschool-hacker-claims-they-stole-data-of-62-million-students/</span></a></p>
Dissent Doe :cupofcoffee:<p>Here's another Canadian school that had decades of student data caught up in the PowerSchool breach:</p><p>Wellington Catholic District School Board:<br><a href="https://www.wellingtonadvertiser.com/cybersecurity-breach-involves-29-years-of-catholic-school-board-data/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">wellingtonadvertiser.com/cyber</span><span class="invisible">security-breach-involves-29-years-of-catholic-school-board-data/</span></a></p><p><a href="https://infosec.exchange/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/legacydata" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>legacydata</span></a> <a href="https://infosec.exchange/tags/EduSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EduSec</span></a> </p><p><span class="h-card" translate="no"><a href="https://infosec.exchange/@douglevin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>douglevin</span></a></span> <span class="h-card" translate="no"><a href="https://freeradical.zone/@funnymonkey" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>funnymonkey</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@brett" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>brett</span></a></span></p>
Dissent Doe :cupofcoffee:<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@douglevin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>douglevin</span></a></span> <span class="h-card" translate="no"><a href="https://freeradical.zone/@funnymonkey" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>funnymonkey</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@brett" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>brett</span></a></span> </p><p>American School of Dubai mentioned as having been affected: <a href="https://www.dmnews.com/school-districts-worldwide-impacted-by-powerschool-breach/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">dmnews.com/school-districts-wo</span><span class="invisible">rldwide-impacted-by-powerschool-breach/</span></a></p><p><a href="https://infosec.exchange/tags/EduSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EduSec</span></a> <a href="https://infosec.exchange/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a></p>
Dissent Doe :cupofcoffee:<p>I must have missed something. I thought PowrerSchool hit US and Canada. It also hit some Bermuda schools? </p><p><a href="https://www.royalgazette.com/education/news/article/20250119/details-given-on-school-security-breach/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">royalgazette.com/education/new</span><span class="invisible">s/article/20250119/details-given-on-school-security-breach/</span></a></p><p>"Ms Richards said the company confirmed the breach included “data from some Bermuda public schools families and teachers”."</p><p><span class="h-card" translate="no"><a href="https://infosec.exchange/@douglevin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>douglevin</span></a></span> <span class="h-card" translate="no"><a href="https://freeradical.zone/@funnymonkey" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>funnymonkey</span></a></span> </p><p><a href="https://infosec.exchange/tags/EduSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EduSec</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/Powerschool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Powerschool</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a></p>
Dissent Doe :cupofcoffee:<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@douglevin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>douglevin</span></a></span> <span class="h-card" translate="no"><a href="https://freeradical.zone/@funnymonkey" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>funnymonkey</span></a></span> <span class="h-card" translate="no"><a href="https://journa.host/@mkeierleber" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>mkeierleber</span></a></span> </p><p>So I could be wrong, but I think the only way they may be able do that for minor kids who don't have a credit report already is to have Experian create a credit report for the minor which they then monitor. </p><p>So now your kid has a credit report, which they never should have had as a minor, and what happens after two years when Experian stops monitoring it? </p><p>Has anyone asked them about that? </p><p><a href="https://infosec.exchange/tags/PowerSchool" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerSchool</span></a> <a href="https://infosec.exchange/tags/EduSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EduSec</span></a> <a href="https://infosec.exchange/tags/IncidentResponse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IncidentResponse</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a></p>