PowerSchool reported a cybersecurity incident involving unauthorized exfiltration of personal information from PowerSchool Student Information System environments through its PowerSource customer support portal. The incident period was reported as December 19 through December 28, 2024, and PowerSchool discovered the incident on December 28, 2024. The Washington Attorney General filing lists January 27, 2025, as the consumer notification date.
The filing identifies 182,122 Washington residents as affected, including 6,412 people whose Social Security numbers were involved. The reported information included names, dates of birth, Social Security numbers, limited medical alert information, contact information, and other related information. A total affected count for all jurisdictions was not stated in the Washington filing. The filing also says the reported figures covered hosted customers that did not opt out of PowerSchool’s notification and excluded on-premises customers.
PowerSchool’s California filing records the same December 19 and December 28, 2024 incident dates and the January 27, 2025 reporting date. Further jurisdiction-specific counts and affected data details may be reported separately as customer and regulatory notices continue to be reviewed.