In December 2024, a nineteen-year-old logged into PowerSchool’s customer support portal with a single stolen password. Nothing else stood in the way. There was no multi-factor authentication behind it, no second check like the texted code or app prompt that’s supposed to stop exactly this kind of entry. One password, and he was in. He left with records on 62 million students and 9.5 million teachers: names, Social Security numbers, medical notes, IEPs, disciplinary files, home addresses, and free-lunch status, which is a quiet proxy for family income. It was the largest breach of children’s data in American history.

PowerSchool paid a $2.85 million ransom in Bitcoin. The hackers kept the data anyway and went back to extort individual districts a few months later. Hold onto that part.

Here’s the uncomfortable turn. The breach is the loud version of something a lot of us are doing a quiet version of every week.

When you paste a student’s essay into ChatGPT with their name and grade level attached, you’ve done a smaller version of what PowerSchool did at scale. You’ve moved sensitive information about a child into a commercial system, secured by terms you didn’t write, to be used in ways you never specifically approved. The scale is wildly different. The shape is identical.

I’m not saying that to scold anyone. I’ve pasted student work into these tools. The point isn’t guilt. It’s that the breach made visible something that was already true, and that we mostly don’t look at.

The contract nobody read

Schools signed up for PowerSchool without most teachers ever knowing they were agreeing to keep Social Security numbers and medical records in a portal with no second lock on the door. Nobody read that contract. There wasn’t really one to read. There was a procurement decision two levels up.

The same thing happens every time a teacher opens an AI tool. The terms of service permit some mix of data retention, training use, and third-party sharing, and they’re written by the company’s lawyers, not your IT department. “We don’t train on your data” is a sentence in a document the same company can revise. FERPA, the federal student-privacy law, was built for a world of filing cabinets and registrar’s offices. It does not cleanly cover a teacher dropping a kid’s essay into a chatbot at nine at night.

And here’s the detail that should stop you. PowerSchool owns Schoology, the learning management system. Same company, same breach. If your school runs Schoology, the vendor that lost 62 million children’s records is also the system holding the demographic data on your students right now. As AI gets built into these platforms, that data doesn’t wait for a teacher to type it in. It’s already inside the building, sitting next to the tool.

Deleted doesn’t mean deleted

The most unsettling part of the PowerSchool story isn’t the break-in. It’s what came after.

They paid the ransom. The hackers had promised to delete the data. They didn’t. Districts got extorted again, months later, with the same files. The company did everything a ransom is supposed to buy, and the data was still out there, because data that has been copied cannot be un-copied. There is no delete button that reaches every server a file has touched.

Student data has a permanence that schools, teachers, and parents haven’t fully reckoned with. A fourteen-year-old’s records don’t expire at graduation. The essay you fed into a tool last spring doesn’t come back when you close the tab. We treat these systems like conversations, things that end. They’re closer to permanent records we don’t control.

The practical move

You don’t fix this by swearing off AI. The tools are useful, and your students are going to spend their lives with them.

You fix it the way a careful teacher fixes most things: decide what the tool actually needs to do its job, and give it nothing more. For feedback, that’s the writing and your rubric, not the writer. Strip the name. Strip the grade level. Strip the “this is one of my IEP kids, go easy” context that feels like diligence and works like a leak. The tool can respond to an essay without knowing whose essay it is.

That one habit—feed the work and not the child—covers most of what FERPA was trying to protect, and it’s available today with no new software.

The PowerSchool breach and the question “should I use AI to grade this?” look like two different stories. They’re the same story at two scales. One is what happens when a company gathers the most sensitive data in children’s lives and guards it badly. The other is what happens, quietly, every time we hand a piece of a student to a system we don’t control and assume it forgets.

It doesn’t forget. That’s the thing worth teaching, and the thing worth practicing ourselves first.

Sources

TechCrunch — PowerSchool paid a hacker’s ransom; now schools say they’re being extorted

TechCrunch — What PowerSchool isn’t saying about its breach

EdWeek — What Schools Should Know About the PowerSchool Data Breach

K-12 Dive — PowerSchool hacker sentenced

The 74 — PowerSchool paid off hackers; now districts being extorted

NMU CTL — Understanding FERPA in the Context of Generative AI

If you’re thinking through questions like this one, my book goes deeper. The AI Doesn’t Know Your Students is available on Amazon and at shouldiuse.ai/book.

Get the next piece before it’s published. One email, most weeks — what I’m seeing in the classroom, nothing else.

🤞 Don’t miss these tips!

We don’t spam! Read more in our privacy policy

David Jacobson teaches high school history in Shanghai. He writes about AI and education at shouldiuse.ai and is the author of The AI Doesn’t Know Your Students.