A new, powerful Citizen Portal experience is ready. Switch now

New Kent Schools: PowerSchool breach likely exposed student records; district awaiting scope and notifications

February 03, 2023 | NEW KENT CO PBLC SCHS, School Districts, Virginia


This article was created by AI summarizing key points discussed. AI makes mistakes, so for full details and context, please refer to the video of the full meeting. Please report any errors so we can fix them. Report an error »

New Kent Schools: PowerSchool breach likely exposed student records; district awaiting scope and notifications
Sean Terry, speaking to the New Kent County Public Schools board, reported that a national PowerSchool credential used for vendor support was compromised and that malicious actors used that access to extract data from PowerSchool systems. "A bad actor gained access to PowerSchool through a maintenance account and a credential that was shared across all PowerSchool instances," Terry said, describing how a single shared support password allowed access across customers.

Terry said logs provided by PowerSchool indicate student data tables were pulled twice, but PowerSchool has not yet confirmed exactly which records from New Kent County Public Schools—if any specific subset—were taken. "So right now, our assumption is all of our student data was taken, and we're waiting to hear back from PowerSchool," he said, while noting that the company is still investigating and obligated to provide legal notices to anyone whose data was breached.

District staff said they have been coordinating with PowerSchool and their risk-management provider, Bacor, and that Bacor advised the division not to undertake its own independent probe to avoid creating legal liability. PowerSchool is offering two years of free credit monitoring to affected individuals, and the division has published a web page with links and guidance assembled by Ashley Meredith based on information from Bacor and PowerSchool.

Board members asked technical questions about hosting, admin accounts, logging, and whether the district's use of cloud versus self-hosting would have mattered. Terry said PowerSchool and CrowdStrike helped identify an IP address tied to the attack and that some vendor-side support accounts had been generic, complicating attribution. He said PowerSchool has changed policies so support accounts are unique per customer and are disabled by default unless a customer explicitly requests them and defines an access window.

The board did not take formal action but directed staff to continue working with PowerSchool, Bacor, and counsel, and to notify families as required by law. Terry said the district will share updates as PowerSchool provides more detail and legal notices are issued.

View the Full Meeting & All Its Details

This article offers just a summary. Unlock complete video, transcripts, and insights as a Founder Member.

Watch full, unedited meeting videos
Search every word spoken in unlimited transcripts
AI summaries & real-time alerts (all government levels)
Permanent access to expanding government content
Access Full Meeting

30-day money-back guarantee