From a school system email:

PowerSchool has informed us that they have taken action with the hackers to ensure the unauthorized data was deleted without any further replication or dissemination. They do not anticipate any of the data being shared or made public and are working with cybersecurity experts and law enforcement to ensure ongoing data safety.  PowerSchool indicated they will be providing credit monitoring to affected adults and identity protection services to affected minors in accordance with regulatory obligations.

  • drascus@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    4
    ·
    11 hours ago

    All systems can be compromised no matter how secure. It sucks that we have to out our kids privacy at risk just to send them to school.

  • sleepydragn1@lemmy.world
    link
    fedilink
    English
    arrow-up
    47
    ·
    edit-2
    1 day ago

    I feel like this is a euphemistic way of saying “we paid the ransom” without actually saying “we paid the ransom.”

      • AmidFuror@fedia.io
        link
        fedilink
        arrow-up
        7
        ·
        1 day ago

        But that is hardly a step toward assuring anything was deleted. Do the criminals really have a reputation at stake for keeping their word? Wouldn’t that require we can confirm their identity?

        • Spaceman9000@infosec.pub
          link
          fedilink
          English
          arrow-up
          7
          ·
          24 hours ago

          It boils down to their reputation, which is honestly the only thing they truly have.

          If they have a reputation of leaking date afterwards nobody is going to pay in the future.

          So afaik, they don’t resell or give it away. They also send “proof of deletion”, but how fool proof that is is another question entirely.

  • BassTurd@lemmy.world
    link
    fedilink
    English
    arrow-up
    36
    ·
    1 day ago

    I’m over this, "we were too incompetent and failed at our job, so your personal information is in the hands of a bad entity. Sry, here’s “monitoring”.

    No. How about you fucking pay me and suffer consequences instead? If you can’t afford to pay thousands to every affected individual and continue being a business, you don’t get to be a business anymore. Equifax and Change Healthcare are two companies I did not opt into using, but had to, and they both fucked up and lost all of my most sensitive information. People should be in jail and I should have thousands of dollars more in compensation. Instead, I got $7 from Equifax and offered free monitoring from CHC. Make it so it’s debilitating when sensitive information is lost, and maybe places would take security more seriously.

          • AmidFuror@fedia.io
            link
            fedilink
            arrow-up
            3
            ·
            1 day ago

            I made a similar comment elsewhere. Are the hackers identifying themselves such that they have a reputation that means something? If so, how do we know they are the reputable hackers and not just using the name of the reputable hackers?

            In blackmail cases, the scammers typically keep coming back for more and more money.

            • x00z@lemmy.world
              link
              fedilink
              English
              arrow-up
              4
              ·
              20 hours ago

              Reputable blackhat hackers often use an online portal where they show proof.

              Lesser known ransomware gangs are definitely known to try and double dip though.

              • nandeEbisu@lemmy.world
                link
                fedilink
                English
                arrow-up
                2
                ·
                3 hours ago

                That’s why you should always check the reviews of any hacking organization before letting them hack you.

            • can@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              2
              ·
              21 hours ago

              I had the same thought. What’s stopping a new party from riding the clout of a “reputable” hacker?

              • Cypher@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                16 hours ago

                There is a whole ecosystem at work where hackers can trade tools, collaborate, announce successes and confirm they are behind a breach.

                The ransomware system relies on the majority of actors following through on their part of the bargain or no one would ever pay a ransom.

                There are many parallels to how the majority of real world piracy was conducted.

  • hedgehogging_the_bed@lemmy.world
    link
    fedilink
    English
    arrow-up
    19
    ·
    1 day ago

    I’m upset about this but I’m way more upset to be finding out about it from Lemmy instead of from my school district or PowerSchool directly. My Pennsylvnaia school district hasn’t said anything about this.

    • TheWilliamist@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      7 hours ago

      I read about it yesterday morning and my school district sent out an email The same evening. I believe had it not been published they would have stayed quiet.

    • jared@mander.xyzOP
      link
      fedilink
      English
      arrow-up
      6
      ·
      edit-2
      1 day ago

      Just got the email a couple hours ago, our district has been shut down all week though.