TechCrunch News 01月08日
Edtech giant PowerSchool says hackers accessed personal data of students and teachers
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

美国教育科技巨头PowerSchool遭遇网络安全事件,黑客通过入侵其PowerSource客户支持门户,获取了学校信息系统PowerSchool SIS的访问权限,导致美国各地K-12学区学生和教师的个人数据泄露。PowerSchool为北美超过75%的学生提供服务,此次事件影响广泛。尽管PowerSchool声明并非勒索软件攻击,但承认支付了赎金以阻止数据泄露。泄露的数据可能包括姓名、地址、社保号码、医疗信息、成绩等个人身份信息。此外,PowerSchool还面临非法出售学生数据的集体诉讼指控。

🚨PowerSchool遭遇网络安全事件:黑客通过入侵其客户支持门户,获取了学校信息系统PowerSchool SIS的访问权限,导致学生和教师的个人数据泄露。

🔒数据泄露范围广泛:泄露的数据可能包括姓名、地址、社保号码、医疗信息、成绩等个人身份信息。尽管PowerSchool声明并非勒索软件攻击,但承认支付了赎金以阻止数据泄露。

⚖️面临集体诉讼指控:PowerSchool还被指控非法出售学生数据,其收集的学生数据高达345TB,涉及440个学区。诉讼称其以教育支持为幌子,为商业利益收集敏感信息。

Education technology giant PowerSchool has told customers that it experienced a “cybersecurity incident” that allowed hackers to compromise the personal data of students and teachers in K-12 school districts across the United States.

The California-based PowerSchool, which was acquired by Bain Capital for $5.6 billion in 2024, is the largest provider of cloud-based education software for K-12 education in the U.S., serving more than 75% of students in North America, according to the company’s website. PowerSchool says its software is used by over 16,000 customers to support more than 50 million students in the United States.

In a letter sent to affected customers on Tuesday and published in a local news report, PowerSchool said hackers successfully breached its PowerSource customer support portal on December 28, allowing further access to the company’s school information system, PowerSchool SIS, which schools use to manage student records, grades, attendance, and enrollment. The letter said the company’s investigation found the hackers gained access “using a compromised credential.” 

PowerSchool has not said what types of data were accessed during the incident or how many individuals are affected by the breach, and neither PowerSchool nor Bain Capital have responded to TechCrunch’s questions. 

The nature of the cyberattack remains unknown. Bleeping Computer reports that in an FAQ sent to affected users, PowerSchool said it did not experience a ransomware attack, but that the company was extorted into paying a financial sum to prevent the hackers from leaking the stolen data. PowerSchool told the publication that names and addresses were exposed in the breach, but that the information may also include Social Security numbers, medical information, grades, and other personally identifiable information. PowerSchool did not say how much the company paid. 

PowerSchool was sued by class action in November 2024, which alleges the company illegally sells student data without consent for commercial gain. According to the lawsuit, the company’s troves of student data totals some “345 terabytes of data collected from 440 school districts.”

“PowerSchool collects this highly sensitive information under the guise of educational support, but in fact collects it for its own commercial gain,” while hiding behind “opaque terms of service such that no one can understand,” the lawsuit alleges. 

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

PowerSchool 网络安全 数据泄露 学生数据 教育科技
相关文章