Article Read Time

A few years ago, I sat across from a senior statewide school administrator, a man whose decisions shaped policy for K-12 schools across the Commonwealth, and explained, plainly, that schools are targets for cyber criminals. He would not have it. Schools, he told me, had nothing a criminal would want. No money to speak of, no secrets, nothing worth stealing. He said it the way a person states the obvious. I have thought about that conversation many times since, because he was wrong, and the cost of being wrong has fallen on children.
In January 2025, a company called PowerSchool disclosed a breach. PowerSchool builds the software that thousands of American school districts use to store student records, and a criminal who obtained stolen passwords accessed those records and extracted data on roughly 62 million students and more than 9 million teachers. For some of them, the stolen files included Social Security numbers, medical notes, and grades. The company paid a ransom of about $2.85 million for a promise that the data would be destroyed. Months later, criminals were still emailing districts samples of the same data, asking for more.
That is the part the administrator missed. A K-12 schools do not have to be rich to be worth robbing. It has to hold something valuable, and a school holds the most valuable thing a thief can carry off: the clean, unused identity of a child.
Here is why that matters. An adult checks a credit report, watches a bank balance, and notices when something is wrong. A seven-year-old does not. A stolen Social Security number belonging to a child can sit unused for a decade, then surface when that child applies for a first car loan, a first apartment, or college aid, only to learn that someone has been using their name for years.
Cleaning it up takes time, money, and proof that a teenager lacks. Security experts now tell families affected by the PowerSchool breach to monitor their children’s credit reports for at least 10 years. That is the long tail of a single break-in, and it lands on people who were in the fourth grade when it happened.
The numbers behind that breach are not a fluke. Between July 2023 and December 2024, 82 percent of K-12 schools in this country experienced a cyber incident. Ransomware attacks on schools, the kind that lock up a district’s files until it pays, rose sharply again in early 2025, with average demands in the United States around half a million dollars. K12 SIX, the nonprofit that has tracked these incidents since 2016, reports that schools now field an average of several cyber incidents every week. This is not a coming storm. It is the weather that schools already work in.
Why schools, and why now? Because schools have what criminals want and little of what stops them. Schools hold rich personal records on children, parents, and staff. They run on tight budgets that rarely leave room for a full-time security staff, and depend on a handful of outside vendors, much like districts depend on PowerSchool, so a single broken vendor can spill data from hundreds of districts at once.
And they are staffed by busy people, teachers, clerks, and bus coordinators, who were hired to educate children, not to spot a fake login page. None of that is a moral failing. It is simply the ground we stand on, and pretending otherwise is how a district ends up in the news.
So what can a district actually do? More than you might think, and most of it does not require a large check.
Start with the front door. A second login step, which means proving who you are with both a password and a code sent to your phone, stops the most common attack cold. The PowerSchool break-in began with a stolen password and an account with no second-factor authentication. Require that second step on every account that touches student data, with no exceptions for the superintendent or the IT director.
Keep a spare set of keys. Back up critical systems often, store at least one copy where a criminal who breaks in cannot reach it, and test that the backups actually restore. A district that can rebuild its own files does not have to pay a ransom to recover them.
Know your vendors. Before a K-12 schools hands student records to an outside company, it should ask plainly: where does this data go, who else can see it, and what happens if there is a breach? Put the answers in the contract. The PowerSchool districts learned the hard way that their data was only as safe as a vendor they could not see.
Teach the staff kindly. Most attacks begin with a single email that tricks one tired person into clicking. Short, regular training, the kind that treats staff as smart adults rather than suspects, does more than any single piece of software. Tell people what a real district email looks like, give them an easy way to report a strange one, and thank them when they do.
Protect the K-12 schools students directly. Lock down student accounts the same way you lock down staff accounts. Teach older students, in plain terms, why their own information is worth guarding. And when a breach reaches student data, tell families promptly what to watch for, because a parent who knows can freeze a child’s credit before the damage starts.
None of this is exotic. It is the civic equivalent of locking the building at night, and a district does not need a federal grant to begin. Free help exists for the parts that are harder. The federal Cybersecurity and Infrastructure Security Agency publishes guidance for schools; K12 SIX shares practical checklists; and most states run emergency management offices that can point a district to real resources at no cost.
The administrator who waved me off was not careless. He was certain, and certainty is the more dangerous of the two. He no longer holds that position, but the districts he once oversaw still carry the records and still carry the risk. The schools that come through the next few years intact will be the ones that traded that certainty for a few plain habits, practiced early, before the email arrives. A child’s name is worth protecting long before that child knows it is in danger. That is the whole job, and it starts with believing the threat is real.
If you help run a K-12 schools district, or a school board, or a single building, and you want a clear-eyed look at where you stand, we are glad to sit down and talk it through. No pitch, no pressure. Just a conversation about your fundamentals and where the gaps are. You can reach Commonwealth Sentinel at 502-234-5554 whenever you are ready, and we will meet you at the kitchen table.
At Commonwealth Sentinel, we stay focused on cyber security so you can focus on other things!
