"PowerSchool is aware that a threat actor has reached out to multiple school district customers in an attempt to extort them using data from the previously reported December 2024 incident," PowerSchool shared in a statement to BleepingComputer. In response to the breach, PowerSchool paid a ransom to prevent the public release of the stolen data and received a video from the threat actor claiming the data had been deleted. PowerSchool is warning that the hacker behind its December cyberattack is now individually extorting schools, threatening to release the previously stolen student and teacher data if a ransom is not paid. Security experts and ransomware negotiators have long advised against companies paying a ransom to prevent the leaking of data, as threat actors are increasingly failing to keep their promise to delete stolen data. In the days following our discovery of the December 2024 incident, we made the decision to pay a ransom because we believed it to be in the best interest of our customers and the students and communities we serve," continued the PowerSchool statement. These databases contained different information depending on the district, including students' and faculty's full names, physical addresses, phone numbers, passwords, parent information, contact details, Social Security numbers, medical data, and grades. This was recently seen in UnitedHealth's Change Healthcare ransomware attack, in which they paid a ransom to the BlackCat ransomware gang to receive a decryptor and not leak data. As first reported by BleepingComputer, the hacker claimed to have stolen the data of 62.4 million students and 9.5 million teachers for 6,505 school districts across the U.S., Canada, and other countries. "Any organization facing a ransomware or data extortion attack has a very difficult and considered decision to make during a cyber incident of this nature. It is believed that UnitedHealth paid a second ransom to once again prevent the leaking of the data.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Wed, 07 May 2025 18:30:00 +0000