LOGO

PowerSchool Password Breach: Malware Steals Credentials

January 17, 2025
PowerSchool Password Breach: Malware Steals Credentials

PowerSchool Data Breach Exposes Millions of Student and Teacher Records

A significant cyberattack and subsequent data breach at PowerSchool, a leading U.S. educational technology company, was detected on December 28th. This incident potentially compromises the private information of a vast number of students and educators.

Breach Origin and Initial Reports

PowerSchool has informed its clientele that the breach stemmed from a compromised account belonging to a subcontractor. However, TechCrunch has independently reported on a separate security event. This involved a PowerSchool software engineer whose computer was infected with malware, leading to the theft of their company credentials before the main cyberattack occurred.

It appears unlikely that the subcontractor referenced by PowerSchool and the engineer identified by TechCrunch are one and the same. The credential theft experienced by the engineer casts additional doubt on the robustness of security practices within PowerSchool, particularly following its acquisition by Bain Capital in a $5.6 billion transaction last year.

Scope of the Data Compromise

Currently, PowerSchool has released limited details regarding the cyberattack to the public. As affected school districts begin notifying students and teachers, the extent of the data breach is becoming clearer.

The company’s website indicates that its school records software serves 18,000 schools, supporting over 60 million students throughout North America.

A communication shared with customers last week and reviewed by TechCrunch confirms that unauthorized actors obtained “sensitive personal information” pertaining to students and teachers. This includes, for some students, Social Security numbers, academic grades, demographic data, and medical records.

While PowerSchool has not yet quantified the number of affected customers, several school districts impacted by the breach have reported to TechCrunch that hackers accessed “all” of their historical student and teacher data.

Details of Exfiltrated Information

An individual connected to an affected school district has provided evidence suggesting the exfiltration of highly sensitive student information. Examples cited include details regarding parental access rights, such as existing restraining orders, and information concerning students’ medication schedules.

Other sources within affected school districts have indicated that the specific data stolen will vary depending on the information each school individually stored within their PowerSchool systems.

Technical Details of the Attack

According to sources speaking with TechCrunch, PowerSchool communicated to its customers that the attackers gained access to the company’s systems through a single compromised maintenance account. This account was associated with a technical support subcontractor.

PowerSchool’s incident page, launched this week, confirms the identification of unauthorized access within one of its customer support portals.

Security Vulnerabilities and Remediation

Beth Keebler, a PowerSchool spokesperson, confirmed to TechCrunch that the subcontractor’s account used in the breach was not secured with multi-factor authentication (MFA). This widely adopted security measure helps protect accounts against hacks resulting from password theft.

PowerSchool has stated that MFA has since been implemented across its systems.

Investigation and Response

PowerSchool is collaborating with incident response firm CrowdStrike to investigate the breach. A report detailing the findings is anticipated as early as Friday.

CrowdStrike deferred all commentary to PowerSchool when contacted by email.

Discrepancies in Reporting

Keebler informed TechCrunch that the company “cannot verify the accuracy” of their reporting. She stated that CrowdStrike’s initial analysis revealed “no evidence of system-layer access associated with this incident nor any malware, virus or backdoor.”

PowerSchool declined to confirm receipt of the report from CrowdStrike or indicate whether it intends to publicly release its findings.

Ongoing Assessment

PowerSchool has indicated that its review of the exfiltrated data is still in progress and has not yet provided an estimate of the number of students and teachers whose data was compromised.

PowerSchool Data Breach: Malware as the Entry Point

An investigation into the recent PowerSchool cyberattack reveals that an engineer’s computer was compromised by the LummaC2 infostealing malware, according to a source familiar with cybercriminal activities. Analysis of logs recovered from the affected device indicates a prior infection.

The precise timing of the malware installation remains uncertain, however, the source indicates the engineer’s passwords were potentially compromised in January 2024, or even before that date.

The increasing prevalence of infostealers represents a growing threat to corporate security. This trend is particularly pronounced with the expansion of remote and hybrid work models, which often involve employees utilizing personal devices for work-related tasks. As highlighted by Wired, this practice introduces vulnerabilities, allowing infostealing malware to infiltrate home computers and subsequently gain access to corporate credentials.

TechCrunch’s review of the LummaC2 logs uncovered the engineer’s passwords, detailed browsing history from multiple web browsers, and comprehensive technical information about their computer system.

Notably, some of the compromised credentials appear to grant access to PowerSchool’s internal networks.

The malware functioned by extracting saved passwords and browsing data from the engineer’s Google Chrome and Microsoft Edge browsers. This stolen information was then transmitted to servers under the control of the malware operator. Subsequently, these credentials were disseminated within online cybercrime communities, including private Telegram groups where corporate account access is bought and sold.

The extracted data includes passwords for PowerSchool’s source code repositories, its Slack communication platform, its Jira bug tracking system, and other critical internal systems. The engineer’s browsing history also demonstrates access to PowerSchool’s Amazon Web Services account, including complete control over the company’s S3 cloud storage servers.

To protect the engineer’s privacy, their identity is being withheld, as there is no indication of wrongdoing on their part. It is crucial to remember that companies bear the ultimate responsibility for implementing robust security measures and policies to prevent breaches resulting from compromised employee credentials.

In response to inquiries from TechCrunch, PowerSchool’s Keebler stated that the individual whose credentials were exploited did not possess access to AWS. Furthermore, they affirmed that PowerSchool’s internal systems—including Slack and AWS—are secured with multi-factor authentication (MFA).

The engineer’s computer also contained credentials belonging to other PowerSchool employees, as confirmed by TechCrunch’s review. These credentials appear to offer comparable access to the company’s Slack, source code repositories, and other internal systems.

A significant number of the PowerSchool credentials found within the logs were characterized by their simplicity and lack of complexity, with some consisting of only a few characters. Moreover, several of these passwords had been previously compromised in prior data breaches, as identified by Have I Been Pwned’s regularly updated database.

For legal reasons, TechCrunch refrained from testing the validity of the stolen usernames and passwords on PowerSchool systems. Consequently, it remains unknown whether these credentials are still active or protected by MFA. PowerSchool indicated they could not comment on the passwords without reviewing them. (TechCrunch deliberately withheld the credentials to safeguard the hacked engineer’s identity.) The company maintains it has “strong password security protocols, including minimum length and complexity requirements, and passwords are rotated in accordance with NIST guidelines.” Following the breach, PowerSchool implemented a “complete password reset and enhanced password and access controls for all PowerSource customer support portal accounts,” which was the point of entry for the attack.

PowerSchool utilizes single sign-on technology and MFA for both its employees and contractors. The company provides contractors with either company-issued laptops or access to a virtual desktop environment equipped with security controls, such as anti-malware software and a VPN for secure system access.

Several questions surrounding the PowerSchool data breach and the subsequent response remain unanswered, as affected school districts continue to evaluate the extent of data stolen from current and former students and staff.

School district personnel impacted by the PowerSchool breach are relying on collaborative efforts from other districts and customers to assist in searching their PowerSchool log files for evidence of data exfiltration.

As of this publication, PowerSchool’s documentation regarding the breach is inaccessible without a valid customer login to the company’s website.

Carly Page provided additional reporting.

Zack Whittaker can be contacted securely via Signal and WhatsApp at +1 646-755-8849, and Carly Page can be reached securely on Signal at +44 1536 853968. Secure document sharing with TechCrunch is possible through SecureDrop.

#PowerSchool#password breach#malware#data security#hack#education security