Your Kid's Data Is Already for Sale
EPISODE 24 | THE PERMANENT RECORD: How School Data Breaches Put Your Child's Identity on the Market

Summary: Public schools have become one of the softest, highest-value targets in the ransomware economy. They hold enormous amounts of sensitive data on children, run on tight budgets with little security staff, and depend on third-party vendors that keep getting breached. This episode maps the current threat landscape: the PowerSchool breach that exposed roughly 62 million students and 9.5 million teachers, the Canvas breach that became the largest education breach on record, the always-on monitoring software watching half the students in the country, and the collapse of the federal support that many districts relied on. Then it covers what districts have to do and, more importantly, what parents and students can actually control. The single highest-leverage action for a parent: freeze your child's credit.
---
Key Stats:
- PowerSchool breach (Dec 2024): roughly 62.4 million students and 9.5 million teachers across 6,505 districts, via one stolen password
- Hacker Matthew Lane (19) sentenced Oct 2025 to 4 years and about $14.1 million in restitution; PowerSchool paid a ransom, data was still used to extort districts
- PowerSchool Naviance settlement: $17.25 million over alleged tracking of student communications, covering roughly 10 million people
- Canvas / Instructure breach (spring 2026): ShinyHunters claimed about 3.65 TB and 275 million records across nearly 9,000 institutions; largest education breach on record
- CISA: K-12 now averages more than one cyber incident per school day
- Roughly half of K-12 students are subject to monitoring software (GoGuardian, Gaggle, Lightspeed); Gaggle alone reports about 6 million students across roughly 1,500 districts
- Federal MS-ISAC funding ended Sept 30, 2025; membership fell from over 18,000 organizations to about 5,600
- Roughly 22% of state, local, tribal, and territorial governments have zero dollars dedicated specifically to cybersecurity
---
Key Cases and Sources:
- [PowerSchool hack exposes student, teacher data (BleepingComputer)](https://www.bleepingcomputer.com/news/security/powerschool-hack-exposes-student-teacher-data-from-k-12-districts/)
- [PowerSchool breach: what families should do (Security.org)](https://www.security.org/identity-theft/breach/powerschool/)
- [What the $17.25M Naviance settlement means (K-12 Dive)](https://www.k12dive.com/news/what-the-1725m-naviance-settlement-means-for-school-districts/816496/)
- [2026 Canvas security incident (Wikipedia)](https://en.wikipedia.org/wiki/2026_Canvas_security_incident)
- [Canvas hack impacts thousands of schools (CNN)](https://www.cnn.com/2026/05/07/us/canvas-hack-strands-college-students-finals-week)
- [Ransomware attacks against the education sector (K-12 Dive)](https://www.k12dive.com/news/ransomware-attacks-against-education-sector-slow-worldwide/811133/)
- [MS-ISAC enters uncertain new era after losing federal funding (Cybersecurity Dive)](https://www.cybersecuritydive.com/news/ms-isac-membership-loss-states-federal-funding-cut/821984/)
- [What we know about the edtech services that watch students (EdSurge)](https://www.edsurge.com/news/2025-10-14-what-do-we-know-about-the-edtech-services-that-watch-students)
- [School surveillance systems threaten student privacy (Knight First Amendment Institute)](https://knightcolumbia.org/blog/school-surveillance-systems-threaten-student-privacy-new-knight-institute-lawsuit-alleges)
- [As cyberattacks increase on K-12 schools (U.S. GAO)](https://www.gao.gov/blog/cyberattacks-increase-k-12-schools-here-whats-being-done)
---
Defenses and Resources:
For districts (CISA guidance):
- [Protecting Our Future: Cybersecurity for K-12 (CISA)](https://www.cisa.gov/topics/cybersecurity-best-practices/K12cybersecurity/protecting-our-future-cybersecurity-k12)
- [Cybersecurity for K-12 Education (CISA)](https://www.cisa.gov/topics/cybersecurity-best-practices/K12cybersecurity)
- [K-12 Ransomware Resources (CISA StopRansomware)](https://www.cisa.gov/stopransomware/k-12-resources)
- [K-12 Cyber Incident Map (K12 SIX)](https://www.k12six.org/map)
For parents and students:
- [How to protect your child from identity theft, including freezing a child's credit (FTC)](https://consumer.ftc.gov/articles/how-protect-your-child-identity-theft)
- [FERPA and your rights over education records (U.S. Dept. of Education)](https://studentprivacy.ed.gov/)
- [Children's privacy and COPPA (FTC)](https://www.ftc.gov/business-guidance/privacy-security/childrens-privacy)
---
The Priority Actions:
Parents (highest leverage first):
1. Freeze your child's credit at all three bureaus (Equifax, Experian, TransUnion). Free, and it blocks new accounts opened with a stolen SSN.
2. Treat any breach notice as real. Take the free monitoring, but know the freeze is what actually prevents fraud.
3. Ask your district what SIS, LMS, and monitoring software it uses, what data each holds, and for how long.
4. Use the opt-outs you already have (FERPA directory information; COPPA protections for younger kids).
5. Decline optional apps and accounts. You cannot leak what was never collected.
6. Talk to your kid: a school device is not private, and what they type on it is recorded.
Districts (CISA priorities):
1. Multifactor authentication everywhere, especially administrator accounts (the PowerSchool entry point was one stolen password).
2. Patch known exploited vulnerabilities.
3. Keep offline, tested backups.
4. Segment the network.
5. Build and rehearse an incident response plan.
6. Manage vendor risk and minimize what data leaves the district.
---
Key Takeaways:
- Schools are a primary ransomware market, not collateral damage: high-value data, low budgets, and a soft attack surface
- A single student record can expose a child's SSN, home address, medical and disability information, disciplinary history, and family income at once
- A child's SSN is the long game: pristine, unmonitored, and usable for years before anyone checks
- Paying ransoms bought nothing in both PowerSchool and Canvas; the data was still used against victims
- Monitoring software builds a behavioral file on minors that carries its own breach and false-positive risk
- The federal safety net (MS-ISAC, the Dept. of Education's ed-tech office) contracted just as attacks hit record scale
- The one action that neutralizes the biggest downstream harm is a parent freezing the child's credit
---
Call To Action:
If your child is in school, freeze their credit this week. It is free, it takes about an hour across the three bureaus, and it closes the exact door a data breach opens. Do that first.
Then send one email to your district and ask three questions: what student information system do you use, what monitoring software runs on my child's device, and how long is my child's data retained. You are entitled to ask, and asking tells them parents are paying attention.
Head to OPSECPodcast.com for the full episode and every link.
Your privacy and your security is your responsibility.