In December 2024, attackers signed into PowerSchool's PowerSource customer support portal with a compromised technical-support subcontractor maintenance credential on an account that had no multi-factor authentication. According to TechCrunch, PowerSchool spokesperson Beth Keebler confirmed the subcontractor's account used to breach the portal was not protected with MFA. After that login, the attackers used legitimate maintenance remote-support tooling to export Students and Teachers table data from customer SIS instances across multiple K-12 districts. Public reporting does not establish how the maintenance credential was first obtained, and PowerSchool has not published exact totals of affected students, teachers, or districts. Password-only support portals still hand attackers a clean login. The rest is just using the tools the vendor already shipped.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

How did attackers get into the PowerSchool PowerSource portal?

The PowerSchool PowerSource support-portal breach started with a single compromised technical-support subcontractor maintenance password on an account that had no MFA. PowerSchool told customers it became aware on December 28, 2024, and public notices began around January 7, 2025. Public reporting does not establish how that credential was initially stolen or leaked.

What student and teacher data left through PowerSource?

After signing into PowerSchool's PowerSource portal, attackers used maintenance remote-support tooling to export Students and Teachers table data from customer student information systems. PowerSchool customer communications viewed by TechCrunch described sensitive personal information on students and teachers, including some Social Security numbers, grades, demographics, and medical information. Several affected districts' logs showed hackers stole all of their historical student and teacher data. PowerSchool has not published a single confirmed total of affected people or districts. TechCrunch cited PowerSchool website figures of about 18,000 schools supporting more than 60 million students in North America; that is product reach, not a confirmed breach headcount.

Was the PowerSource portal compromised with malware?

No. For the PowerSchool PowerSource incident path, Beth Keebler said CrowdStrike's initial analysis showed no evidence of system-layer access and no malware, virus, or backdoor. The documented entry was credential-only portal sign-in, then use of legitimate support export tooling. Separate TechCrunch reporting on LummaC2 password theft from a PowerSchool engineer endpoint is not established as this portal intrusion path.

Did attackers bypass MFA on the PowerSource account?

No. MFA was not enabled on the breached PowerSchool PowerSource support account, so there was nothing to bypass. Keebler told TechCrunch the subcontractor account used to breach the customer support portal was not protected with multi-factor authentication. PowerSchool later said it rolled out MFA on the affected portal path, ran a full password reset, and tightened password and access controls for PowerSource customer support portal accounts.

Whose account was used, and what could it reach?

The PowerSchool PowerSource breach used a technical support subcontractor maintenance account on the customer support portal, not a general employee session into every internal system. Keebler said the person whose compromised credentials were used did not have AWS access, and PowerSchool said internal systems including Slack and AWS are protected with MFA. The blast radius that mattered was privileged support access into customer SIS data through remote-support maintenance tooling after portal authentication.