Data from the North Carolina’s student and teacher information system — containing personal and private information about the state’s schoolchildren and teachers — was compromised last month, but officials say it has been destroyed.
Still, state officials said Wednesday that PowerSchool is working with law enforcement agencies to monitor the Internet — including the dark web — to ensure none of the data is published online, a tactic hackers have used in other school data breaches. The company will also provide credit monitoring to affected adults and identity protection services to minors whose social security numbers were exposed to hackers.
Other WRAL Top Stories
It’s unclear so far whether all students or districts were affected, and officials are still working that out.
People can never be 100% sure breached data is destroyed, said Cliff Steinhauer, director of information security and engagement at the National Cybersecurity Alliance.
"You have to put your trust in the attackers who are going to say that they destroyed it and that they're going to abide by their word," he said.
PowerSchool notified the North Carolina Department of Public Instruction and the state's school systems of the breach at about 2 p.m. Tuesday, according to Jeanie McDowell, a department spokeswoman. That was 10 days after the company says they discovered the breach — Dec. 28.
“NCDPI is aware of this issue and is actively working with PowerSchool to obtain more information,” McDowell wrote in an email to WRAL News. “Protecting student and educator data is a top priority, and we take this matter very seriously.”
McDowell said the breach occurred when the credentials of a PowerSchool contract employee were compromised and that compromised data has been destroyed.
PowerSchool told the agency the “threat began” Dec. 19 and was discovered Dec. 28.
When asked why the company waited until Jan. 7 to notify DPI, Beth Keebler, a PowerSchool spokesperson, told WRAL News via email the company prioritizes providing “all necessary details to our customers as soon as possible, while ensuring accuracy in our investigation and information shared.”
Students and parents in the affected schools and school systems in North Carolina will eventually be notified of the breach. Vanessa Wrenn, the department’s chief information officer, said the department is working with PowerSchool on that task.
In statement, a PowerSchool spokesperson said the company had taken “all appropriate steps to prevent the data involved from further unauthorized access or misuse. The incident is contained and we do not anticipate the data being shared or made public.”
Still, many parents are nervous.
Sontina Barnes, a Wake County parent, has already had one of her children's social security numbers stolen, years ago. Someone tried to file taxes with it.
"It's a real concern to me to have my kids' information out there, anywhere," she said.
What data was accessed
The company deactivated the compromised account and restricted access to the affected data portals.
PowerSchool is still reviewing the incident, but company officials believe the unauthorized actor took data from two tables, both that primarily include contact information for families and educators. For some customers, those tables can include social security numbers and other personally identifiable information. Customers, such as DPI, can tailor their use of PowerSchool to include or not include certain information. It’s unclear if North Carolina had social security numbers in those tables.
Wrenn told WRAL News the department believes demographic information is primarily what was illicitly accessed. She doesn’t expect medical or individualized education plan information to be included.
Even if a school has already begun using Infinite Campus — which will eventually replace PowerSchool statewide — their data from prior years is still in PowerSchool, Wrenn said.
PowerSchool is the state’s hub of essential student data. Beyond names and birthdates, it holds information on grades, disciplinary actions, test scores, contact information, busing information, attendance, demographic information and many other datapoints. The state has more than 1.5 million public schoolchildren and about 100,000 teachers.
WRAL News reached out to districts that still primarily use PowerSchool about when they learned of the breach and what they planned and when to communicate to staff and families about the breach, including Wake, Durham, Chatham, Franklin and Chapel HIll-Carrboro school systems.
Crystal Roberts, a spokeswoman for Durham Public Schools, said only that the “we’ve not been notified by our Research & Accountability office of any adverse effects from this breach.” The district is still looking into whether its students were affected.
The Wake and Chapel HIll-Carrboro districts told WRAL News they haven’t received confirmation that their students were affected by the breach.
Sara Clark, a Wake schools spokeswoman, said DPI is assessing the North Carolina impact.
“Once we receive more information, we will determine next steps,” Clark said.
Andy Jenks, a CHCCS spokesman, said the district is awaiting advice on whether it needs to take any actions.
McDowell said the breach affected the company’s entire client base, which extends to millions of students worldwide.
“PowerSchool is committed to protecting the security and integrity of our applications,” the company’s statement to WRAL News says. “We take our responsibility to protect student data privacy and act responsibly as data processors extremely seriously… PowerSchool is committed to providing affected customers, families, and educators with the resources and support they may need as we work through this together.”
Moving to a new system
North Carolina is transitioning away from PowerSchool — a decision made last year — and to Infinite Campus. A handful of school districts are piloting Infinite Campus this year but most are still on PowerSchool until the statewide transition in July.
School data breaches — and attempted breaches — are increasingly common. Data concerning minors is seen as more appealing to hackers because of the lack of public records about minors and the potential ease of stealing their identities.
Steinhauer said attacks are more commonly directed at schools themselves, than a software providers.
Breaches in school systems have resulted in publicly published information about students, including in Minneapolis and Los Angeles.
From 2016-2022, the K12 Security Information eXchange reported 1,619 known cybersecurity incidents in K-12 schools.
Deanne Cranford-Wesley, director of North Carolina Central University’s cybersecurity lab, said cybersecurity breaches are common now.
“It’s not about if you’re going to have a breach, it’s when,” she said. “We think we have enough control, but these hackers are getting more advanced everyday.”
Cranford-Wesley recommended that people take advantage of any information and credit monitoring that may be offered, just in case.
Steinhauer recommended the same.
"It's really important to freeze your credit and monitor your credit reports so that either you're catching fraudulent accounts being open or you're preventing them in the first place with a credit freeze," he said.
Preventing future attacks?
On Wednesday, Wrenn told the State Board of Education that there was nothing DPI or North Carolina schools could have done to prevent the breach. Still, she said, a third party, CrowdStrike, is working with PowerSchool to learn more about how the breach occurred.
Wrenn said what they know so far is the PowerSchool contractor’s credentials were compromised in a malware attack. Then, the unauthorized individual or group wrote a script to copy data from PowerSchool and used a “maintenance tunnel” in the system to export it. When PowerSchool learned of the incident, they worked with the unauthorized party to ensure the data was destroyed, Wrenn said.
School districts don’t need to take any “technical” action, she said.
Superintendent Mo Green told the board the department is “on top of it” and “we will continue to do everything we need to do to ensure that the data we collect is secure.”
He said DPI may not need to make any changes in response to the breach, because the breach was out of DPI’s control.
“But it may be something that causes us to say, ‘Let’s be sure that we do something even better the next time,’” he said.