PowerSchool

Update 3/13/25

Update 3/7/25

Timeline

1/7/2025: Email sent to our district data manager and our district network manager stating our district data was extracted by the perpetrator. Confusingly, our district's IT Director and two of our district data clerks received separate PowerSchool (PS) emails stating “other PowerSchool products” were not affected. 

1/8/2025: Following a PowerSchool's recommendation during a scheduled webinar, our data manager contacts our PowerSchool CSM (Customer Service Manager) and PS support to confirm whether or not WCS data was accessed.

1/9/2025: (12:28 PM) Superintendent receives an email from the Tennessee Department of Education Chief Information Officer that PowerSchool has reported a data breach that likely has impacted several Tennessee district customers; (5:36PM) PS releases communication guidance to districts.

1/10/25: (1:06 PM) Superintendent receives a follow up email from the Tennessee Department of Education Chief Information Officer that PowerSchool has confirmed the data breach as well providing specific details of the services to be provided by PS in mitigating. Included in the CIO email was an email address for districts to report the confirmed breach of district data to the Tennessee Comptroller and Attorney General; PowerSchool Support confirms WCS data was accessed by the perpetrator.

1/13/2024: WCS finalized and released general notification letters with available details to all current parents via our district communication system. WCS finalized and released general notification letters with available details to all current employees via our district communication system.

1/17/2025: PowerSchool has released additional details and guidance for families and educators. See FAQs at https://www.powerschool.com/security/sis-incident/

1/24/2025: Status Update released by PowerSchool. See https://www.powerschool.com/security/sis-incident/

1/29/2025: Identity and Credit Monitoring Update. See https://www.powerschool.com/security/sis-incident/

3/7/2025: Summary Update. See https://www.powerschool.com/security/sis-incident/

The following dates were reported to us by PowerSchool during the 1/8/2025 and 1/9/2025 webinars and communications releases:

12/19/2024: PowerSource, a PowerSchool support module, is breached via compromised credentials. Perpetrator subsequently uses a backdoor to download teacher and student information over the course of 4 days.

12/22/2024: Perpetrator downloads WCDE information (confirmed by PowerSchool on 1/10/2025).

12/28/2024: PowerSchool discovers security breach.