LIVE
UTC --:--:--
OT SECURITY HUB
by zuckergates
// INCIDENT · 2025

PowerSchool K-12 Data Breach

Penyedia SIS K-12 terbesar AS mengalami pencurian data masif melalui akun support tanpa MFA.

highUSA/CAEducation
Impact
62 juta siswa & guru K-12 (data SSN, medis) terekspos; tebusan dibayar tapi data tetap diperjual.
Initial vector
Compromised support credential → PowerSource
Lessons learned
  • MFA pada vendor support tools
  • Minimisasi data siswa
  • Disclosure cepat distrik sekolah