Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
education-sector-threatthird-party-vendor-breachbreach-disclosure-notificationoperational-disruption

PowerSchool Breach Exposed Student and Teacher Data as Minnesota District Faced Suspected Ransomware

Updated 28d agoFirst seen May 25, 20264 sources

A breach tied to PowerSchool, a widely used K-12 software provider, exposed student and teacher information from school districts across the U.S., including New Jersey districts where officials said data on students and educators was stolen in a nationwide cyberattack. Reporting on the incident said the compromise affected records held by schools using the platform, raising concerns about the scale of exposure across the education sector and the security of sensitive K-12 data.

Separately, Spring Lake Park Schools in Minnesota canceled classes and shut down technology systems after an outside actor gained unauthorized access to district networks in what officials described as a suspected ransomware incident. The disruption affected classes, child care, community education, and after-school programs, while the district worked with third-party cybersecurity experts, state law enforcement, and the FBI to contain the intrusion and restore operations; officials later said classes would resume and that they had no evidence at that point that personal information had been affected.

Share:
PowerSchool Breach Exposed Student and Teacher Data as Minnesota District Faced Suspected Ransomware
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 14, 20262mo ago

Spring Lake Park says athletics resume and classes to reopen

As restoration progressed, Spring Lake Park said high school athletics and activities would resume Tuesday and classes would reopen Wednesday. The district also said state law enforcement and the FBI were involved in the investigation and that it had no evidence personal information was affected at that time.

Apr 13, 20262mo ago

Spring Lake Park closes schools and programs after cyber incident

The district canceled classes for Monday and Tuesday following the intrusion, and the outage also disrupted child care, community education, and after-school activities on Monday. Officials said some systems required to operate schools safely were unavailable.

Apr 12, 20262mo ago

Unauthorized access detected in Spring Lake Park school systems

Spring Lake Park Schools said its technology team confirmed on Sunday that an outside actor had gained access to some district systems. Staff shut down systems to prevent further access and contain the incident.

Jan 9, 20251y ago

New Jersey reports student and teacher data stolen in nationwide attack

New Jersey officials disclosed that data about students and teachers was stolen as part of the broader nationwide cyberattack tied to school systems. This marked a state-level impact disclosure connected to the larger breach.

Jan 7, 20251y ago

PowerSchool discloses breach affecting K-12 student and teacher data

PowerSchool disclosed a cyberattack that exposed student and teacher information from K-12 school districts. The incident was reported as affecting districts nationwide.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.