PowerSchool faces new extortion attempts following educational data theft
PowerSchool reported extortion attempts against school districts following a data breach that occurred in late 2024.

News summary
PowerSchool reported extortion attempts against school districts following a data breach that occurred in late 2024. The affected information could include personal data of students and staff.
Paying does not guarantee that the information will vanish. Data minimisation, limited permissions, encryption and monitoring for anomalous access reduce exposure before a breach occurs.
Source: Reuters — 7 May 2025
What happened
In May 2025 PowerSchool, an education management software provider, reported new extortion attempts against school districts following a data theft that occurred in late 2024. The affected information could include personal data of students and education staff.
The company had initially paid to prevent the stolen data from being released, but the new extortion attempts showed that this payment did not guarantee the information would disappear or not be used again against victims.
What it means for a mid-sized business
The case illustrates a specific risk for software providers that centralise data from many customers: a single breach can affect dozens or hundreds of organisations at once, each with its own obligation to notify affected individuals.
For a business that contracts this kind of service, the lesson is that a provider's security is part of its own risk, and paying a ransom is no guarantee the problem ends there.
What to review
Measures that reduce exposure before a breach occurs at a provider:
- Data minimisation: share only the information strictly necessary with providers.
- Encryption of sensitive personal data, both in transit and at rest.
- Clear contractual clauses on security, incident notification and provider liability.
- Monitoring of anomalous access to data managed by the provider on the company's behalf.
Frequently Asked Questions
- What data was affected?
- According to PowerSchool, personal information of students and education staff stored on its school management platform.
- Did paying the ransom solve the problem?
- Not permanently. The new extortion attempts in May 2025 show the initial payment did not stop the data being used again to pressure victims.
- What can a business demand from a software provider handling sensitive data?
- Minimisation of shared data, adequate encryption and clear contractual commitments on security and incident notification.
Concepts mentioned in this article: Monitoring
Technology only adds value when it is well-designed, protected and maintained. Seintec can help you land these best practices in your company; speak with our team to assess your environment.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.