Malware stole internal PowerSchool passwords from engineer’s hacked computer
ID: cc85f54b-da84-5b6c-90ef-f6ae486ce485
STIX ID: report--cc85f54b-da84-5b6c-90ef-f6ae486ce485
Feed Name: TechCrunch Security News
PowerSchool disclosed a cyberattack discovered on December 28 that may have exposed sensitive personal information for students and teachers — including Social Security numbers, grades, demographics, and medical information — after attackers used a compromised maintenance account belonging to a technical-support subcontractor to access a customer support portal. TechCrunch reports that an engineer’s computer was previously infected with the LummaC2 infostealer, which harvested credentials (including access to Slack, source code repositories, Jira, and potentially AWS/S3) and that stolen credentials were circulated in cybercrime forums; the subcontractor account reportedly lacked MFA. PowerSchool is working with CrowdStrike, has rolled out MFA and reset passwords, and affected school districts are still assessing the scope of exfiltrated data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
