Close Menu
globalcrimedesk.comglobalcrimedesk.com
    What's Hot

    Can South Africa Mend Ties With the U.S.?

    Premium WordPress ‘Motors’ theme vulnerable to admin takeover attacks

    International Tea Day: Spilling the tea on unusual teas around the world | Infographic News

    Facebook X (Twitter) Instagram
    Trending
    • Can South Africa Mend Ties With the U.S.?
    • Premium WordPress ‘Motors’ theme vulnerable to admin takeover attacks
    • International Tea Day: Spilling the tea on unusual teas around the world | Infographic News
    • UN: Start Talks on Treaty to Ban ‘Killer Robots’
    • Israel-Gaza war live: Israel ‘very close’ to committing war crimes, says former PM as UN warns aid still being blocked | Israel
    • George Wendt, aka Norm on ‘Cheers,’ has died : NPR
    • South Africa’s Ramaphosa to meet Trump at White House : NPR
    • Nvidia CEO Jensen Huang labels US GPU export bans ‘wrong’ • The Register
    Facebook X (Twitter) Instagram
    globalcrimedesk.comglobalcrimedesk.com
    • Home
    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention
    • Scandals
    • Terror
    • Trafficking
    globalcrimedesk.comglobalcrimedesk.com
    Home»Cyber»PowerSchool hacker pleads guilty to student data extortion scheme
    Cyber

    PowerSchool hacker pleads guilty to student data extortion scheme

    mediamillion1000@gmail.comBy [email protected]May 21, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
    Follow Us
    Google News Flipboard
    PowerSchool hacker pleads guilty to student data extortion scheme
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    PowerSchool hacker pleads guilty to student data extortion scheme

    A 19-year-old college student from Worcester, Massachusetts, has agreed to plead guilty to a massive cyberattack on PowerSchool that extorted millions of dollars in exchange for not leaking the personal data of millions of students and teachers.

    According to the U.S. Department of Justice, Matthew D. Lane pleaded guilty to four federal charges of one count each of cyber extortion conspiracy, cyber extortion, unauthorized access to protected computers, and aggravated identity theft.

    The DOJ and court documents state that Lane and his conspirators breached a US-based telecommunications company in 2022, where they stole confidential customer information. During this breach, they also gained access to PowerSchool credentials belonging to an employee at the telecommunication company that acted as a contractor for PowerSchool.

    After attempting to extort the telecom firm, the DOJ says they conducted an attack on an education company that would pay a ransom.

    “On or about May 14, 2024, LANE messaged CC-1 that if Victim 1 did not pay the ransom, LANE and CC-1 could sell the Stolen Victim 1 Data. LANE further suggested, ‘we need to hack another . . . company that[‘]ll pay’,” reads the DOJ complaint.

    While the complaint does not explicitly mention PowerSchool, sources told BleepingComputer that they are the education company referred to by the DOJ.

    The complaint says that the threat actor used the credentials stolen from the PowerSchool contractor to breach the company and steal data for millions of students and faculty in December 2024.

    As previously reported by BleepingComputer, threat actors breached PowerSchool’s support platform, PowerSource, and used a maintenance tool to download the school’s databases. These databases included the personal information of 62.4 million students and 9.5 million teachers from 6,505 school districts in the US, Canada, and other countries.

    This data consisted of different information depending on the district, including students’ and faculty’s full names, physical addresses, phone numbers, passwords, parent information, contact details, Social Security numbers, medical data, and grades.

    The DOJ says that PowerSchool received a ransom demand for approximately $2.85 million in Bitcoin on December 28, 2024. The threat warned that if payment was not made, the stolen data would be leaked “worldwide.”

    While BleepingComputer previously reported that PowerSchool paid a ransom demand to prevent the leak of data, it is still unclear how much was paid.

    However, even after PowerSchool paid the ransom, the threat actors attempted to individually extort impacted school districts into paying further ransoms not to leak student data.

    According to school notices and DataBreaches.net, these ransom demands claimed to be from Shiny Hunters, a prolific group of threat actors known for a wide range of breaches, including the SnowFlake data theft attacks and a 2022 data breach at AT&T that impacted 109 million people.

    While many of the threat actors involved in the SnowFlake and AT&T attacks have been arrested over the past year [1, 2, 3], it’s possible that other members carried out the attacks, or that copycats are attempting to plant a false flag

    In addition to the PowerSchool breach, Lane also faces charges for the attempt to extort the U.S.-based telecommunications company, where they demanded a $200,000 ransom and made threats against company executives if the ransom was not paid.

    Lane has agreed to plead guilty to all four counts and faces a mandatory minimum sentence of two years for identity theft and up to five years on each of the other charges.

    Red Report 2025

    Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

    Data extortion guilty Hacker pleads PowerSchool Scheme student
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleJapanese minister resigns after saying he doesn’t buy rice because he gets it free | Japan
    Next Article Judge warns US deportations to South Sudan may breach court order
    [email protected]
    • Website

    Related Posts

    Premium WordPress ‘Motors’ theme vulnerable to admin takeover attacks

    May 21, 2025

    Nvidia CEO Jensen Huang labels US GPU export bans ‘wrong’ • The Register

    May 21, 2025

    Software Bill of Material umsetzen: Die besten SBOM-Tools

    May 21, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Latest Posts

    Can South Africa Mend Ties With the U.S.?

    Premium WordPress ‘Motors’ theme vulnerable to admin takeover attacks

    International Tea Day: Spilling the tea on unusual teas around the world | Infographic News

    UN: Start Talks on Treaty to Ban ‘Killer Robots’

    Trending Posts

    Can South Africa Mend Ties With the U.S.?

    May 21, 2025

    Premium WordPress ‘Motors’ theme vulnerable to admin takeover attacks

    May 21, 2025

    International Tea Day: Spilling the tea on unusual teas around the world | Infographic News

    May 21, 2025

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    News

    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention

    Company

    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy policy
    • Terms & Condition
    Recent Posts
    • Can South Africa Mend Ties With the U.S.?
    • Premium WordPress ‘Motors’ theme vulnerable to admin takeover attacks

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 globalcrimedesk. Designed by Pro.
    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

    Type above and press Enter to search. Press Esc to cancel.