PowerSchool Breach: 5 Million Victims Will Reach Adulthood Before Justice is Served
Please note all IPC investigation files relating to this matter are now closed.
That’s the sentence I received in response to my privacy complaint about the PowerSchool breach and extortion event of December 2024.
“Closed.”
On paper, maybe. In real life, the effects of this breach will run quietly in the background of millions of people’s lives for decades. The files may be closed, but the risk isn’t.
And for me, this wasn’t a surprise plot twist. My career in helping to secure school systems started years earlier with a different edtech vendor: Edsby.
Back in 2017, Edsby left data from my school board exposed to enumeration attacks, allegedly including up to 120,000 students. That incident, followed by other messy events in other provinces, is what pushed me to create EdtechPrivacy.ca as Canada’s first mechanism for conducting due diligence on the innovative companies that often claim to need access to children’s data in order to ‘deliver value’. It’s also sparked a
niche as I’ve been partnering with the Knowledgeflow Cybersafety Foundation to educate teachers on how to protect student data, from parsing privacy policies to developing a spidey sense around unwarranted overcollection.
So when PowerSchool and their new owner, Bain Capital enter the story, I am not coming at this as a shocked bystander. This is the sequel no one asked for, but everyone could see coming.
1. The numbers that should make every parent sit down
Let’s start with scale.
In Alberta, the investigation names 33 educational bodies, including large boards like Calgary Board of Education, Rocky View, Elk Island Catholic, and a Francophone regional authority. The commissioner estimates that over 700,000 individuals were affected in that province alone. These are not just “user accounts” in a dashboard; they are students, parents or guardians, and staff, with information such as names, addresses, phone numbers, dates of birth, student IDs, medical alerts, health information, and in some cases social insurance numbers.
In Ontario, 20 school boards plus the Ministry of Education reported the breach. The Ontario commissioner estimates that about 3.86 million Ontarians had their information affected. Across Canada, that same report estimates roughly 5.2 million Canadians impacted, as the same PowerSchool SIS platform and support portal were used in multiple provinces and territories.
A student information system (SIS) is a software platform that manages and stores all student-related data for educational institutions, automating administrative tasks like admissions, enrollment, grading, and attendance. It centralizes student information, making it forever accessible to administrators, teachers, parents, and students through a central hub, allegedly improving communication and supporting data-driven decision-making. This includes such simple things as the task of taking attendance using a cloud-based system that tracks student locations down to the classroom. It’s progress of a kind. Or, as our school board’s CTO famously called it: “modernizing the attendance process”.
I call it the answer to the questions no one was asking. Other than the data brokers behind these edtech ‘innovators’, of course.
What then, do cybercriminals call it? Opportunity.
Because where there’s hubris, there’s profit.
So, just between those two reports, we are already talking about 4.5 to 5 million real people in one country whose data was exposed through a vendor that exists, in theory, so schools can manage attendance and print report cards more efficiently.
Let’s zoom out of Canada just for a moment.
The U.S. criminal case related to the same breach describes the attackers boasting about access to data for more than 60 million students and around 10 million teachers connected via PowerSchool’s massive database.
At that point you’re not running “a breach.” You’re running an unauthorized population study. And that may have been just the ‘value’ that Bain Capital saw in PowerSchool when it paid 5600 million dollars for it. You read that right. 5.6 Billion dollars to buy children’s data. And data of people who used to be children, but no longer are.
2. Just how long were they holding onto this stuff?
The Ontario Privacy Complaint Report includes a figure showing how far back some of the compromised data went. It reads like a school system version of tree rings.
A few highlights:
- Peel District School Board: student and parent data going back to 1965. That’s Binders full of Children’s Data (ahem!).
- Simcoe Muskoka Catholic DSB: secondary school data from 1984, elementary from 2003, plus educator data from those eras.
- London District Catholic: adult education data from 1993, K–12 from 2008.
- Toronto District School Board: student data from 1985, educator data from 2006.
- Ministry of Education: student and educator data dating back to 1999.
I could go on.
So this was not just about kids currently in class. Adults in their 30s, 40s, 50s and older had their school and work histories quietly stored in a cloud system at the moment the attacker came knocking.
Imagine people like me, who used to take comfort in knowing that our lame student assignments and embarrassing test results would be lost to time because they long predated “the cloud”, suddenly found out that their academic histories still ended up on the interwebs, on someone else’s computer. Or in Mitt Romney’s proverbial binders.
Our Privacy Commissioners both note that some institutions collected more sensitive information than necessary and retained personal information far longer than necessary, which “exposed massive volumes of personal data” and amplified the risk of harm.
Translation into everyday terms:
That note about your childhood asthma, your change of address after a family breakup, or the time your guardian status shifted because of a court order was still sitting in a database in 2024.
In Alberta, the report alarmingly details compromised student records that included addresses, dates of birth, medical information, personal health numbers, and court-related guardianship notes.
3. What actually happened, in plain language
I personally attended the initial, live, PowerSchool mea culpa meetings, and they weren’t pretty. But here’s the core of the story from both reports, so we can get a really good sense of just how wrong things went.
The setup
PowerSchool runs a Student Information System (SIS) that stores student, parent, and staff information for K–12 education: enrolment, attendance, medical alerts, grades, and so on.
Many school boards also used PowerSource, a central support portal that allowed PowerSchool staff to remotely access those SIS environments for troubleshooting.
Think of PowerSource as a backstage pass that lets support staff walk into different school “rooms” to fix things.
The break-in
According to the investigations:
- On December 19, 2024, a threat actor began using compromised credentials belonging to a PowerSchool support person to access PowerSource.
- Using that account, the attacker triggered a remote support function that opened multiple SIS databases and siphoned data from at least two core tables: students and teachers/educators.
- PowerSchool discovered the attack on December 28, 2024 and removed the attacker on December 29.
- Canadian institutions were notified around January 7, 2025, even though some contracts required breach notice within 24 to 72 hours.
So, for those keeping track, the ingredients of this unsavory story were:
- A privileged support account
- A portal that can open SIS instances for maintenance
- A remote access feature that, in practice, was often left effectively always on
It’s like leaving the school safe wired to a remote locksmith “just in case,” and then being surprised when someone copies the keys.
The earlier warning they could not see:
The Alberta report reveals that PowerSource logs showed suspicious use of those same credentials as early as August 16, 2024, but the logs did not go back far enough to reconstruct what happened. The root cause: log retention settings were too short.
In security terms, they had an alarm system with a short-term memory.
4. Ransom, promises and “secure deletion”
Once the attacker had exfiltrated the data, they sent PowerSchool a ransom demand on December 28, 2024. PowerSchool paid.
Then in May 2025, some boards, including TDSB and PDSB, received a second ransom demand tied to the same data.
PowerSchool’s public explanation was:
- They paid the ransom
- They were shown a video of the data being “securely deleted”
- They were told it would not be published
The Ontario commissioner’s gently worded response is: institutions should never rely on assurances from a threat actor. Once the data is stolen, it should be treated as compromised indefinitely.
In parallel, the 19-year-old at the center of the U.S. case pleaded guilty and received a four-year sentence for cyber extortion and unauthorized access, including demands for around 2.85 million USD worth of Bitcoin tied to tens of millions of student and teacher records.
So yes, the individual who pulled the fire alarm has been dealt with. The people who installed the wiring so the alarm could trigger this loudly are still in their offices.
5. Where Bain Capital fits into this
PowerSchool is not a small niche app. It is a large, private equity owned platform sitting on decades of children’s data.
In 2024, Bain Capital acquired PowerSchool in a $5.6 billion deal. That is not a price tag you pay for a simple gradebook; that is the going rate for an infrastructure layer that holds identity, history and relationships for entire school systems.
Bain, for its part, has spent years under scrutiny for business practices such as:
- Loading companies with debt in ways that led to layoffs or closures while still delivering profit to investors.
- Union-busting allegations, including a case at Key Airlines where a union was crushed after a highly leveraged buyout.
- Its role in South Africa’s revenue agency scandal, which led to findings of “grave misconduct” and a UK ban from certain public contracts for a period.
So we have public education systems trusting a private, highly financialized vendor with the most sensitive kind of data there is: information about children and educators.
At that point, a robust vendor risk program is not optional homework. It is table stakes.
6. What the commissioners actually found
Both reports land on the same core conclusion: public institutions did not have reasonable measures in place to protect the personal information they handed to PowerSchool.
Ontario: “Did not have reasonable measures”
The Ontario commissioner found that:
- Institutions did not have reasonable measures to prevent unauthorized access through PowerSchool, as required under FIPPA and MFIPPA.
- Contracts with PowerSchool often lacked strong provisions on security, retention, destruction, audit rights and breach notification timelines.
- Many institutions over-collected and over-retained sensitive data, exposing “massive volumes” unnecessarily.
- Breach response plans were fragmented or inadequate, leading to a disjointed response.
And importantly: institutions remain legally responsible even when a third party hosts the systems. You can outsource the service, not the law.
Alberta: “Did not meet their security obligations”
The Alberta commissioner came to a parallel conclusion under section 38 of the old FOIP Act:
- The 33 educational bodies involved did not make reasonable security arrangements against unauthorized access, use or disclosure.
- Many had weak or missing policies for vendor management, security and data retention.
- PowerSchool’s security, particularly around remote access, privileged accounts, multi factor authentication and monitoring, was below the standard required, and boards are accountable for that.
Both watchdogs are clear: this is not “just how tech works.” This is how weak governance works.
7. The “always on” remote access problem
A particularly uncomfortable section in both reports focuses on remote support.
The Alberta investigation found that:
- PowerSource allowed staff with the right permissions to remotely access customer SIS instances.
- In many cases, this remote support feature was persistently enabled, creating a standing open link.
- Some Alberta boards did not even know this feature existed until after the breach.
PowerSchool argued that the feature was not universally “on by default,” but the commissioners noted that:
- In practice, many educational bodies experienced it as always on.
- PowerSchool’s own corrective actions included removing the “always on” option and limiting maintenance access to time-bound windows, which indirectly confirms the original design was too permissive.
The Ontario report adds that multi factor authentication was not enabled on PowerSource at the time, despite internal policies that required MFA where supported.
In 2024, leaving a global support console for student databases without enforced MFA is not a minor oversight. It is a design decision with predictable consequences
8. Over-collection and over-retention in normal human terms
Over-collection sounds abstract, so let’s ground it.
Imagine:
- The note about a one-off allergic reaction in Grade 2.
- The record of who picked you up after school during a messy custody transition.
- The temporary address used when a family was in crisis housing.
- A teacher’s health accommodation or part-time medical leave arrangement.
Some of this information is essential at the time. None of it needs to follow a person silently for 30 or 40 years through every system that touches their identity.
Yet the reports describe systems where boards kept historical data in SIS environments for decades, and in Alberta, where sensitive items such as court order information and treaty numbers were kept available in day-to-day systems rather than carefully minimized and retired.
The Ontario commissioner is explicit: institutions over-collected and did not purge sensitive data when it was no longer required.
This is how a single breach becomes a long-term background risk, not because criminals are superhuman, but because systems were built to remember everything and forget almost nothing.
9. Accountability ping-pong: “We thought they were doing it”
Another recurring theme is what I’d call “accountability ping-pong.”
- Several boards told the Ontario IPC they relied on PowerSchool’s security commitments, marketing materials or general documentation instead of doing deeper due diligence.
- Some Alberta bodies pointed to contract clauses as if ticking “we have an agreement” was the same as “we understand the risk and manage it”.
PowerSchool, in turn, pointed to certifications, policies and standards, and in some instances argued that the scope of exfiltrated data might be narrower than boards feared.
Both commissioners responded with a simple reminder: under public sector privacy laws, the institution remains responsible for what its vendors do with personal information.
You cannot upload your legal duty along with your student roster.
10. The homework: do the basics, properly
Between them, the Ontario and Alberta reports lay out dozens of recommendations. None of them are exotic. They include:
- Harden remote access and require multi factor authentication anywhere that can reach student data.
- Extend log retention so that suspicious patterns can be detected and investigated.
- Rewrite contracts to clearly cover security standards, retention and destruction rules, breach notification timelines, audit rights and enforcement.
- Stop collecting sensitive information “just in case” and commit to regular deletion schedules.
- Conduct and update privacy impact assessments for major systems and vendor relationships.
- Provide boards, especially smaller ones, with centralized procurement support and technical guidance so they aren’t individually trying to evaluate global vendors with minimal resources.
This is exactly the kind of material I’ve been teaching in sessions through KnowledgeFlow and on EdtechPrivacy.ca for years: basic, practical steps to keep student data from becoming collateral damage in someone else’s incident.
Every school board could book a session tomorrow, bring their leadership teams, and walk out with a concrete plan to avoid repeating this. The open question is: will they choose to?
11. What this means for Canadians, especially kids
For millions of Canadians, this breach is not a news story. It is simply part of the new background noise in their lives.
- If you were a student in one of the affected boards, your school history may now live in a place it was never meant to be.
- If you taught or worked there, your contact details, identifiers and sometimes income or SIN data may be in the same dataset.
The commissioners underline that there’s no evidence so far of a massive data dump on the dark web, but also that institutions should assume stolen data might resurface and should be prepared to respond.
For a six-year-old in 2024, that means the footprints of their childhood in school systems might still matter when they’re applying for a job, a mortgage or a visa decades from now, even if they never know why a particular form already seems to “know” them a little too well.
12. Final grade for public education on privacy
If we were to mark this like a teacher, it might look something like:
- Ambition to digitize and centralize: A
- Vendor management: D
- Remote access configuration: F
- Multi factor authentication coverage: F
- Data retention discipline: F, with creativity
- Breach response preparedness: “Please see me after class.”
But even that risks making this feel like just another unit test.
This isn’t just a technical failure. It is a trust failure.
Parents and students gave schools deeply personal information expecting it would be treated like something closer to a passport than a newsletter mailing list. Instead, we ended up with modern-looking systems, weak guardrails, long memories and short accountability.
The encouraging part is that the path forward is not mysterious. The reports spell it out in detail. The practical training and support already exist. I helped build some of it, exactly because of earlier edtech incidents like Edsby’s.
The uncomfortable part is that the same people who signed the first round of contracts now have to admit the gaps and fix them.
So if you are a trustee, superintendent, ministry official or vendor executive, here is the short version:
You have been handed a multi-province, multi-million person case study in what not to do with children’s data. Treat it as a wake-up call, not a weather report.
Because for students and families, this will not fade with the headline cycle. It will show up quietly, years from now, when someone looks at a form and wonders:
“Why does this system already know so much about me?”
And if you are wondering what to do next, start here:
- EdtechPrivacy.ca for practical guidance on evaluating and governing edtech.
- Knowledgeflow.org to bring real, hands-on cybersafety and privacy education into your board.
The breach may be over, but its repercussions are just starting to cascade. And justice is nowhere in sight for the victims. So feel free to keep filing privacy complaints, because you have the right to clearly understand how much of your family’s information was owned by Bain Capital, and how it will be used for identity fraud in the years to come.
