Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
education-sector-threatenforcement-actionmass-credential-exposurethird-party-vendor-breach

PowerSchool Breach Hacker Sentenced After Extorting Student and Teacher Data

Updated 28d agoFirst seen May 25, 20265 sources

Matthew Lane, a Massachusetts student, pleaded guilty and was later sentenced in a federal case tied to the breach of education software provider PowerSchool, an intrusion U.S. authorities described as the largest cyberattack in U.S. education history. Prosecutors said Lane used stolen contractor credentials and vulnerability-scanning tools to access the company’s network, then threatened to publish sensitive records unless he was paid about $2.85 million in Bitcoin. The compromised data reportedly covered roughly 60 million students and 10 million teachers, including names, phone numbers, addresses, Social Security numbers and, in some cases, medical information.

Authorities said Lane also extorted a separate telecommunications company for $200,000 by threatening to release customer data. The case triggered ransom payments and White House Situation Room briefings, and investigators later found that some stolen PowerSchool data was allegedly retained by another actor and reused in follow-on extortion attempts against school districts. Lane received a four-year federal prison sentence and was ordered to pay more than $14 million in restitution, while U.S. investigators continue pursuing alleged co-conspirators.

Share:
PowerSchool Breach Hacker Sentenced After Extorting Student and Teacher Data
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Oct 17, 20258mo ago

Lane is sentenced to four years and ordered to pay restitution

By April 2026, Lane had pleaded guilty and received a four-year federal prison sentence for his role in the PowerSchool breach. He was also ordered to pay more than $14 million in restitution, while investigators continued pursuing alleged co-conspirators.

May 21, 20251y ago

U.S. prosecutors announce Lane will plead guilty

The U.S. Attorney's Office for the District of Massachusetts announced that Matthew Lane would plead guilty to charges tied to the theft and extortion of data from PowerSchool and a separate telecommunications company. The charges included cyber extortion conspiracy, cyber extortion, unauthorized access to protected computers, and aggravated identity theft.

May 7, 20251y ago

Rogue actor reuses retained PowerSchool data in follow-on extortion

After Lane's arrest, some of the stolen PowerSchool data was allegedly kept by a rogue actor and later used in additional extortion attempts against school districts. This indicated the breach continued to create downstream risk beyond the initial intrusion.

Dec 28, 20241y ago

Attackers extort PowerSchool over stolen student and teacher data

After accessing PowerSchool, Lane and co-conspirators allegedly threatened to release data belonging to about 60 million students and 10 million teachers unless they were paid roughly $2.85 million in Bitcoin. The stolen information reportedly included names, phone numbers, Social Security numbers, addresses, and medical histories.

Matthew Lane breaches PowerSchool using stolen credentials

Prosecutors said Matthew Lane used stolen login credentials to access the network of a software and cloud storage provider serving school systems, identified by reporting as PowerSchool. The intrusion exposed highly sensitive student and teacher data held by a provider used by much of North American K-12 education.

PowerSchool pays ransom after the breach

ABC News reported that the PowerSchool breach prompted ransom payments following the theft of education records. The incident was serious enough to trigger White House Situation Room briefings.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.