Skip to main content

Secur-IT Data Solutions – Toronto – Canada

featured powerschool data breach canada schools 1

PowerSchool Breach Exposes Canadian School Boards – Protecting Your Child’s Data

Canadian Schools Hack

In a concerning development, multiple Canadian school boards, including the largest in the country, the Toronto District School Board (TDSB), have been affected by a significant data breach involving PowerSchool, a widely used student information system. This breach, which occurred between December 22 and 28, 2024, has potentially compromised decades of student data, raising alarms about the security of personal information in educational institutions.

What Happened?

The breach involved unauthorized access to PowerSchool’s Student Information System (SIS) through PowerServe, a customer portal. The compromised data includes students’ names, addresses, dates of birth, phone numbers, and in some cases, more sensitive information like medical records and social insurance numbers. Here’s a detailed look at how the breach unfolded:

  • Initial Compromise: The breach was first identified when it was determined that an unauthorized party had gained access to customer data by compromising a credential. This credential was associated with a back-end account used to offer school boards technical support with the platform.
  • Scope of the Breach: The breach affected school boards in Ontario, Alberta, Newfoundland and Labrador, Nova Scotia, and other provinces. The TDSB, for instance, reported that data from students enrolled between September 1985 and December 2024 might have been accessed.
  • Data Accessed: The compromised data includes students’ names, addresses, dates of birth, phone numbers, and in some cases, more sensitive information like medical records, health card numbers, and social insurance numbers.
  • Response: PowerSchool has taken steps to prevent further unauthorized access, stating that the breach is “contained” and that it does not anticipate the data will be shared or made public. School boards are working with PowerSchool to assess the impact and have notified relevant privacy commissioners.

Steps for Parents to Protect Their Children’s Information:

  1. Verify the Breach:
    • Contact your child’s school to confirm if their information was involved in the breach. Schools might not have all the details immediately, but they should be able to provide updates as the investigation progresses.
  2. Assess the Risk:
    • Determine what types of data were compromised. Sensitive information like social security numbers or medical records poses a higher risk for identity theft or fraud.
  3. Take Immediate Action:
    • Change Passwords: Update passwords for all school-related accounts, ensuring they are strong and unique. Consider using a password manager for better security.
    • Enable Two-Factor Authentication: Add an extra layer of security to your accounts by enabling two-factor authentication wherever possible.
    • Monitor Financial and Credit Activity: Regularly check your child’s credit report for any unauthorized activity. You can also place a credit freeze on their credit files to prevent new accounts from being opened.
  4. Educate Your Children:
    • Discuss the importance of cybersecurity with your children. Teach them about creating strong passwords, recognizing phishing attempts, and being cautious with personal information online.
  5. Stay Informed and Vigilant:
  6. Report Suspicious Activity:
    • If you notice any signs of identity theft or unauthorized use of your child’s information, report it to law enforcement or relevant authorities immediately.
  7. Advocate for Better Security:
    • Engage with school administrators to push for stronger cybersecurity measures, including advanced firewalls, encryption, and regular security audits.

Additional Measures:

  • Secure Your Home Network: Ensure your home Wi-Fi is secure with a strong password and consider using a VPN for added protection.
  • Backup Important Data: Regularly back up important data to mitigate the risk of data loss in case of a cyberattack.
  • Stay Updated: Keep all software, including antivirus programs, up to date to protect against known vulnerabilities.

Conclusion:

The recent cyberattack on Canadian school boards underscores the critical need for robust cybersecurity practices in educational institutions. By taking proactive steps, parents can help protect their children’s personal information from misuse. Remember, cybersecurity is a shared responsibility, and staying informed and vigilant is key to safeguarding our digital lives.

Resources:

  • CBC News: Cyberattack on PowerSchool exposes data of students in multiple Canadian school boards
  • The Record: PowerSchool breach exposes data of students in multiple Canadian school boards
  • PowerSchool: PowerSchool Security Incident Notification

Questions to ask when a service provider holds your data

A breach at an education technology supplier affecting many boards at once shows how concentrated risk becomes when an entire sector uses the same platform. Whether you are a school board, a clinic or a business, the questions are the same.

  • What exactly do they hold? Ask for a written list of the fields. Organizations are regularly surprised by how much historical data a supplier retained.
  • How long do they keep it? Records for people who left years ago are common and rarely necessary. Retention limits are one of the few controls that reduce breach impact directly.
  • Who can access it, and is that access logged? Support staff at a vendor often have broad access. Ask whether that access is monitored and reviewed.
  • How quickly will they tell you? Notification timelines belong in the contract, because you have your own obligations that depend on knowing early.
  • What happens at the end of the contract? Deletion should be contractual and confirmable, not assumed.

For individuals whose information is caught up in a breach involving young people, the practical advice is to treat it as a long term exposure rather than an immediate one. Data about a child can sit unused for years before it is misused, so a credit freeze where available and vigilance about accounts opened in that name matter more than watching for a single fraudulent charge.

Organizations should also remember that outsourcing the processing does not outsource the accountability. Under Canadian privacy law the organization that collected the information remains responsible for it, including when a supplier is the one that loses it.

How Secur-IT Data Solutions can help

We help organizations assess the suppliers holding their most sensitive records, get useful answers to the questions above, and put practical requirements into contracts at renewal. We also help build the breach response process that a supplier incident will eventually require you to run. We work with organizations across Toronto and the GTA as their managed security provider, and we are happy to start with a conversation rather than a quote. Get in touch with our team and we will tell you honestly whether this is something you need help with or something you can close yourself.

Share article

Let’s Connect

Need advice or you have an inquiry to discuss? We would love to hear from you.

Related Cybersecurity Articles