In December 2024, a 20-year-old college student used stolen credentials to access PowerSchool's customer support portal and exfiltrate the personal records of approximately 62 million students and 9.5 million teachers across more than 6,500 school districts. It was the largest breach of children's data in United States history.[1]
PowerSchool paid a $2.85 million ransom. The attacker provided a video purporting to show the data being deleted. The attacker then turned around and extorted individual school districts directly, proving the deletion video was fabricated.[3]
This is the world that districts are procuring SEL curriculum into.
The Breach Landscape
PowerSchool: 62 Million Student Records
62M
Students
6,500+
Districts
$17.25M
Settlement (CPS)
$2.85M
Ransom paid
Stolen credentials on a support portal. SSNs, dates of birth, addresses, medical alerts. Data going back 20+ years. Attacker extorted districts after being paid. Cybersecurity experts now recommend credit freezes for kindergartners.[1][2][4]
Canvas/Instructure: 275 Million Records Claimed
275M
Records claimed
8,809
Institutions
1,616
K-12 Districts
2×
Breached twice
Same ShinyHunters group as PowerSchool. Breached twice in one month. 3.65 TB of data including private student-teacher messages. Instructure paid an undisclosed ransom. Dept. of Education issued a Technology Security Alert.[10][11][12][14]
Illuminate Education: 1.7M Students, $5.1M Settlement
Credentials from an employee who left 3.5 years earlier still worked. Failed to encrypt data at rest. Ignored a 2020 security warning. First enforcement under California's KOPIPA. FTC consent order requiring data deletion.[5][6][7]
Minneapolis: Mental Health Records Published Online
Refused $1M ransom. Medusa group published 300,000 files: sexual misconduct cases, child abuse inquiries, mental health crisis records, suspension reports. Not academic records — records of children's most vulnerable moments.[8]
Gaggle/Vancouver: 3,500 Sensitive Records Exposed
Student poems, essays, and AI chat transcripts collected by a monitoring tool exposed through unprotected links. No password. No encryption. No access controls. Data collected for “safety” was accessible to anyone.[9]
Paying the ransom does not work
PowerSchool paid $2.85M for a deletion video → attacker extorted districts anyway. Instructure paid an undisclosed ransom → received “shred logs.” Independent verification of data destruction is not possible.
Once data is exfiltrated, it is gone. The only protection is not having it stored.
What This Means for SEL
SEL data is uniquely sensitive
When Minneapolis published mental health crisis records, it exposed exactly the kind of information that SEL platforms routinely collect: emotional assessments, behavioral flags, intervention notes, check-in responses. The difference between those records and the data on an SEL vendor's servers is not sensitivity — it is whether the breach has happened yet.
Every vendor is a potential breach vector
PowerSchool: stolen credentials. Illuminate: ex-employee credentials (3.5 years old). Gaggle: unprotected links. Minneapolis: ransomware. Canvas: same group exploiting systems twice. The methods vary. The result is the same. These are not obscure vendors — they are dominant platforms.
The regulatory environment is tightening
All 50 states have breach notification statutes. State AGs are pursuing vendors. FTC consent orders. Settlements in the millions. 59% of districts report higher cyber insurance premiums. The cost of storing student data now includes legal exposure, insurance, notification, and remediation.[8][10]
The SEL Procurement Question
The question is not whether your vendor's security is good enough. PowerSchool's was supposed to be. Illuminate's was supposed to be. The question is whether the curriculum needs to generate the data that creates the risk.
Digital SEL platform stores:
- • Student names and identifiers
- • Mood check-in responses
- • Emotional self-assessment data
- • Behavioral incident records
- • Teacher notes on SEL development
- • Progress monitoring data
- • Intervention flags
Each point = breach risk you don't control
Device-free, account-free curriculum stores:
Nothing
No student records to breach. No emotional assessments in a database. No mood check-ins on a cloud platform. No data to exfiltrate, extort, or expose.
Zero breach exposure
What Districts Should Do
Audit your current SEL vendor's data practices
Request a complete inventory: what data is collected, where stored, who has access, retention period, and what happens if the contract ends or vendor is acquired.
Evaluate breach history and security posture
Ask directly whether the vendor has experienced a breach. Review their incident response plan. Ask who bears breach notification costs — vendor or district.
Assess whether the data is necessary
For every data point collected, ask: does this improve instruction enough to justify breach risk? If no, the data should not be collected.
Consider separating instruction from assessment
Let the curriculum teach. Let a validated screener (DESSA, Panorama) measure. Don't require both from a vendor whose primary competency is content, not data security.
Reduce your vendor footprint
Every vendor storing student data is a breach vector. A device-free SEL curriculum removes one vendor from the data governance landscape entirely.
The Calculation
62M
PowerSchool records
275M
Canvas records claimed
$22.35M
In settlements
2
Ransoms paid (neither verified)
1
FTC consent order
18 mo
Timeframe for all of this
The simplest way to protect children's social-emotional data is to choose a curriculum that never collects it.
References
- TechPolicy.Press. (2026). Unmasking EdTech's Surveillance Infrastructure in the Age of AI. techpolicy.press
- EdCircuit. (2025). PowerSchool Data Breach 2025: What Schools Must Know. edcircuit.com
- Cloudskope. (2025). PowerSchool Breach 2025: 60M Student Records. cloudskope.com
- Captain Compliance. (2026). The PowerSchool Settlement. captaincompliance.com
- The Data Advisor (WilmerHale). (2025). EdTech Provider $5.1M Settlement. wsgrdataadvisor.com
- GovTech. (2025). Ed-Tech Company Reaches Settlement Over Data Breach. govtech.com
- JD Supra. (2025). FTC's Illuminate Education Order. jdsupra.com
- Stingrai. (2026). Education Data Breach Statistics 2026. stingrai.io
- University of Washington. (2025). Privacy by Design Framework for LLM Applications for Children. arxiv.org
- National Cybersecurity Alliance. (2026). Canvas Data Breach. staysafeonline.org
- K-12 Dive. (2026). 2nd Canvas data breach causes major disruptions. k12dive.com
- Tech Insider. (2026). Instructure Canvas Breach: 275M Records. tech-insider.org
- Reed Smith. (2026). Canvas/Instructure Cyberattack: Key Developments. reedsmith.com
- U.S. Dept. of Education, FSA. (2026). Technology Security Alert: Canvas LMS. fsapartners.ed.gov
No Data Stored. No Data to Breach.
Be The Buffalo collects zero student data. No accounts. No logins. No emotional assessments stored on any server. The teacher projects the lesson. The class participates together. Full SEL instruction with zero breach exposure. Because data that doesn't exist can't be stolen.
Sign Up FreeRelated Resources
FERPA and K-5 SEL Curriculum
The three federal laws that govern SEL data and the eight questions every district should ask before purchasing.
Why Teachers Don't Use What Their Districts Buy
The structural gap in EdTech procurement and what it means for SEL adoption.
SEL Without Screens
Why device-free, teacher-led SEL instruction eliminates data privacy concerns.
SEL Curriculum for Elementary Schools
How to evaluate and choose a CASEL-aligned SEL curriculum for K-5 schools.
