PowerSchool Breach: Are Accomplices Still At Large, with the Database in Hand?

by John McClane | Aug 22, 2025 | News Analysis, Commentary and Opinion

The Public School System Failed to Protect Student Data, Plea Deal Indicates There are Accomplices Still Unaccounted For

As New Hanover County Schools and other districts across North Carolina prepare to transition to a new student information system, Infinite Campus, they do so on the heels of the 2024 PowerSchool data breach. At the same time, major questions remain unanswered about the PowerSchool incident, which exposed tens of millions of personal records and led to a multimillion-dollar extortion scheme:

  • Who, beyond Matthew D. Lane, was involved in orchestrating the breach?
  • What steps are districts taking to ensure Infinite Campus avoids similar vulnerabilities?
  • What options remain for PowerSchool victims who missed the credit monitoring deadline?

PowerSchool Hacker Pleads Guilty: College Student at Center of Data Breach Worth Billions

On May 21, 2025, Matthew D. Lane, a 19-year-old student at Assumption University in Worcester, Massachusetts, formally pleaded guilty to multiple federal charges related to the PowerSchool breach. Prosecutors say Lane was the malicious actor behind a sophisticated cyberattack that compromised the personal data of over 62 million students and 9.5 million educators from more than 6,500 school districts across the United States.

Lane admitted to stealing data from PowerSchool and demanding a $2.85 million ransom in Bitcoin. The company paid the ransom.

This wasn’t Lane’s first foray into cyber extortion. Court documents also reveal that he previously extorted a telecommunications company for $200,000, using similar methods. Investigators say Lane stored stolen data on Ukrainian-hosted servers, part of what prosecutors suggest was a broader infrastructure designed to conceal his tracks and monetize the data over time.

Although Lane has taken responsibility, cybersecurity experts and his own plea document point to the idea that he did not act alone. The scope of the breach, the use of foreign infrastructure, and the complex processes required to monetize stolen data all point toward a larger, coordinated network of accomplices. Matthew Lane’s plea agreement includes a guilty plea to violating 18 U.S.C. § 371, which covers conspiracy to commit an offense or to defraud the United States. Under this statute, a conspiracy charge requires at least two participants, meaning Lane’s plea constitutes an admission that he conspired with one or more accomplices to defraud the government. Although Lane is the only individual publicly charged thus far, the 18 U.S.C. § 371 charge confirms that federal authorities believe others were involved in the PowerSchool breach and ransom scheme.

The U.S. Attorney’s Office for the District of Massachusetts has not announced any additional arrests. But according to Bitdefender’s Hot for Security blog, the sheer volume of exfiltrated records, coupled with offshore hosting and multi-layered encryption, strongly suggests Lane was aided by others with advanced technical capabilities.

Leah B. Foley, representing the U.S. Attorney's Office, stated:

“Cyber extortion is a serious attack on our economy and on all of us. As alleged, this defendant stole private information about millions of children and teachers, imposed substantial financial costs on his victims, and instilled fear in parents that their kids’ information had been leaked into the hands of criminals – all to put a notch in his hacking belt. The alleged ransoms that this defendant and others like him demand hurt victim companies and their innocent customers whose data the companies are entrusted to hold.”

The Staggering Value of Student Data: Why Hackers Targeted PowerSchool

Cybercrime researchers estimate that the data stolen from PowerSchool could be worth more than $6 billion on the dark web. Student records are highly valued because they often contain long-term personally identifiable information (PII), such as Social Security numbers, birthdates, addresses, and in some cases, medical and disciplinary records. According to cybersecurity firmDeepStrike, student records can fetch $100-$350 per profile on illicit marketplaces. With tens of millions of records exposed in the PowerSchool breach, the total potential value of the stolen data could amount to hundreds of millions of dollars, possibly billions over students' lifetimes.

Given the immense value of the stolen data, those still at large may attempt to quietly sell the information in small batches. This slow-drip approach would help them avoid setting off red flags in financial systems, keeping the breach an active crime for years.

(Below) WECT News reported that the North Carolina Attorney General will be investigating PowerSchool on the data breach.

Cloud Hosting vs. Local Servers: Weighing the Risks for School Data Systems

Despite the high-profile PowerSchool breach, the new Infinite Campus system will also operate in the cloud, again relying on third-party infrastructure to safeguard student information. Yet officials have not clearly explained whether Infinite Campus offers any significant security improvements over PowerSchool. This uncertainty has led some in the New Hanover community to question whether cloud-based systems are more vulnerable than managing servers in-house.

According to Dawn Brinson, NHCS assistant superintendent of technology and digital learning, bringing SIS systems in-house is financially more expensive and may not necessarily be more secure. Hosting software locally would require significant hardware investments, dedicated cybersecurity staff, and ongoing maintenance and compliance oversight. Despite the expense, Brinson explains that locally hosted systems still may not meet the level of security provided by established, cloud-native providers. While this may be true, there is no way confirm if any vendor is abiding by best practices. The fact remains: PowerSchool was the industry leader relying on cloud services until they were breached.

The estimated black market value of NHCS student and employee data ranges from $3 to $10 million. Still, Vice Chair Josie Barnhart pushed back against a proposal to fund local hosting for applications used by the district, citing potential job losses. Her comments suggest that preserving payroll ranks higher than mitigating student and personnel security risks.

Barnhart also emphasized at length that there are conversations behind the scenes to make systems more secure, but gave no further information.

(Below) Dawn Brinson gives the New Hanover County school board a presentation on the costs of bringing current cloud applications in-house. 

(Below) WECT News reports that North Carolina Department of Public Instruction (DPI) renewed a contract with PowerSchool for one of its services. This contract runs through December 2025, even as it prepares to fully transition districts to Infinite Campus.

About PowerSchools' Woefully Inadequate Credit Monitoring Offer for Students

Most parents assume the credit monitoring offered by PowerSchool will protect their children until adulthood, but that isn’t the case. For minors, including students as young as first grade, the package only provides identity protection for the next two years. Because children generally don’t have credit files, they are not eligible for the credit monitoring portion until they turn 18. By then, the two-year coverage window will have long since expired.

This means a six- or seven-year-old impacted by the breach will receive only short-term protection, even though their stolen Social Security number and personal data could be exploited years later. Identity thieves often hold onto children’s information until they reach adulthood, when it can be used to open fraudulent accounts. In effect, PowerSchool’s offer leaves the youngest victims exposed during the very years when their risk of hidden identity theft is highest.

Lingering Threats from the PowerSchool Breach May Haunt Victims for Years

The PowerSchool breach has exposed serious weaknesses in how public schools safeguard student data, raising urgent questions about the system's ability to protect the privacy of children in its care. While Matthew D. Lane has pleaded guilty, the data he stole was likely duplicated and is still in the dark web.

For tens of millions of students, parents, and teachers, the long-term impact of the breach remains uncertain. It could be years before the full consequences for their financial and personal security are understood. And yet, the most basic questions still haven't been answered. What exactly makes Infinite Campus more secure than PowerSchool? Who were Lane’s accomplices, and where are they now? The inability, or unwillingness, of public school leaders to answer these questions speaks volumes.

Certainly, some parents are beginning to question whether withdrawing their children from public schools is the only way to ensure their personal information remains secure. The system has proven itself time and again to be untrustworthy with your child. This go-around shows educators are incapable of preventing the theft of sensitive personal data.

Stay caught up. Visit the News Roundup on our homepage for the latest headlines, updated twice daily.

Submit a Correction

Name(Required)

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Related Posts

This field is for validation purposes and should be left unchanged.

Support Local Independent News and Analysis!

Amid widespread left-leaning media bias, our role is pivotal. Your sponsorship supports local and regional story coverage, aiding our expansion.