PowerSchool Data Breach Incident
In January 2025, PowerSchool notified Burbank School District 111 of a significant data breach affecting school districts worldwide, including Burbank School District 111. This breach has raised concerns about data security and student privacy, prompting immediate action and ongoing efforts to mitigate potential risks.
Overview
The recent PowerSchool data breach has raised concerns across various school districts, including Burbank School District 111. While specific details about the impact on our district are still emerging, we are committed to keeping our community informed.
This page provides an overview of the incident, its impact on Burbank School District 111, and measures being taken to protect affected individuals.
What happened?
In late December 2024, an unauthorized party accessed PowerSchool’s Student Information System (SIS) data using compromised credentials. This breach affected over 18,000 districts, including Burbank School District 111. The attacker gained access to specific data by exploiting a support contractor’s compromised account.
PowerSchool promptly disabled the compromised account, reset all affected credentials, and notified law enforcement. They have engaged independent cybersecurity experts to investigate the breach further.
Frequently Asked Questions (FAQ):
What is a data breach?
A data breach occurs when unauthorized individuals gain access to confidential information stored on systems or networks. This can involve sensitive personal data and may lead to identity theft, financial fraud, or other risks for affected individuals. Learn more: What is a Data Breach?
What is PowerSchool, and how is it used in Burbank School District 111?
PowerSchool is a widely used Student Information System (SIS) that helps schools manage various aspects of student data, including enrollment, attendance, grades, and schedules. At Burbank School District 111, PowerSchool provides a secure platform for parents, students, and staff to access important academic and administrative information. It supports communication and data tracking to ensure effective educational services.
Learn more: PowerSchool at Burbank School District 111
What information was involved for Burbank School District 111?
For students:
-
Names (first, middle, last)
-
Birthdates
-
Addresses
-
Phone numbers
-
Gender
-
Ethnicity/race
-
Language
-
School name and state
-
Student ID numbers (school and state)
-
Guardian alert and names
-
Enrollment information
-
Lunch waiver information
-
PowerSchool login ID
For staff:
-
Names (first and last)
-
Email addresses
-
School abbreviation codes
-
Teacher numbers (Staff IEIN stored here)
-
PowerSchool login ID (not active due to SSO with Microsoft 365)
Note: No social security numbers, passwords, photos, financial information, or staff home addresses were involved in the breach. PowerSchool’s systems for student and staff photos and financial data are managed separately and were not accessed.
How has PowerSchool responded to the incident?
PowerSchool has:
-
Deactivated the compromised credential and restricted access to the affected portal.
-
Conducted a full password reset and tightened password and access controls.
-
Engaged a professional cybersecurity advisor to negotiate with the threat actor. They received assurances that the accessed data has been deleted without replication or dissemination.
-
Strengthened their password policies, including increased password complexity and length.
-
Notified affected SIS customers to communicate with stakeholders effectively
What actions have been taken?
We are actively collaborating with PowerSchool to assess the extent of the breach and its impact on our district. Our Technology department is also reviewing our internal security measures to ensure the continued protection of our students' and staff's personal information.
What is District 111 doing to protect your data?
Burbank School District 111 is committed to safeguarding student and staff data and works to ensure compliance with data privacy laws such as:
-
The Family Educational Rights and Privacy Act (FERPA) (Learn more about FERPA)
-
The Student Online Personal Information Protection Act (SOPIPA) (Learn more about SOPIPA)
We regularly review and update our data security measures. All contracts with third-party vendors include provisions to protect data confidentiality and comply with state and federal privacy laws. Additionally:
-
District staff receive training on data privacy and security best practices.
-
We have stringent agreements with all third-party vendors to ensure student data remains secure and is used only for authorized educational purposes.
What should staff and families do to protect myself?
- PowerSchool is offering two years of complimentary identity protection and credit monitoring through Experian.
- For individuals 18 and over
-
- Use activation code CTYU949PRK.
- Engagement number: B138812
- For individuals under 18:
- Use activation code CEBP456TRK
- Engagement number: B138813
- Enrollment deadline: May 30, 2025.
- Enroll through the Experian IdentityWorks website.
Recommended Actions:
- Monitor financial statements for suspicious activity.
- Place a fraud alert or security freeze on credit reports for enhanced protection.
- PowerSchool will never contact you by phone or email to request personal information.
- For assistance, contact Experian’s customer care team at 833-918-9464.
Additional Resources:
-
-
PowerSchool Notice of Data Breach For Individuals in the United States:
- Federal Trade Commission (FTC) – Identity Theft Protection:
https://www.consumer.ftc.gov/topics/identity-theft -
Equifax – Fraud Alerts and Credit Freezes:
https://www.equifax.com/personal -
Experian – Credit Monitoring Services:
https://www.experian.com -
TransUnion – Identity Theft Resources:
https://www.transunion.com
-