PowerSchool customers face new extortion threats with previously stolen data
On May 7, 2025, PowerSchool warned that the hacker responsible for its December 2024 cyberattack was individually extorting school districts.
Key points
- New extortion attempts reported on May 7, 2025.
- Threat actors using data stolen in a December 2024 PowerSchool breach.
- PowerSchool had previously paid a ransom for data destruction, which was not honored.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
Organization
- Published
- May 7, 2025
- Updated
- Jun 26, 2026
- Confidence
- Medium
- Evidence
- 2 sources
Structured assessment
Signal analysis
This analysis groups the signal by industry, likely incident action and impacted security area.
Threat source
Watch exposure paths that could affect data, operations or third-party trust.
Mentioned entities
Quick context
Questions about this signal
What happened in this signal?
On May 7, 2025, PowerSchool warned that the hacker responsible for its December 2024 cyberattack was individually extorting school districts. The threat actors are using previously stolen student and teacher data, which PowerSchool had paid a ransom to have destroyed, to demand further payments. Samples of the data match the information stolen in the earlier incident. North Carolina school districts and the Toronto District School Board were among those targeted by these new extortion attempts.
When was this signal reported?
Shadow Tier lists May 7, 2025 as the signal date.
Which organization is connected to this signal?
Powerschool is the organization connected to this public signal.
Explore PowerschoolWhich impact area is relevant?
This signal is connected to data exposure and breach intelligence based on its reported consequences.
Explore data exposure and breach intelligence