PowerSchool hacker got four years in prison

PowerSchool hacker got four years in prison

PowerSchool hacker got four years in prison

Pierluigi Paganini
PowerSchool hacker got four years in prison October 17, 2025

PowerSchool hacker got four years in prison

Matthew D. Lane, a Massachusetts student, got four years in prison for hacking and extorting $3M from PowerSchool and another company.

A Massachusetts student, Matthew D. Lane, was sentenced to four years in prison for hacking and extorting about $3 million from two companies, including PowerSchool.

In May, Lane pleaded guilty to hacking two U.S. companies, including likely PowerSchool, and extorting them.

The student used stolen credentials to access a company serving schools in the US, Canada, and beyond, hacking its network in September and December 2024. He exfiltrated student and teacher data (including names, addresses, birth dates, emails, Social Security numbers, and medical info) and demanded $2.85 million in Bitcoin, threatening to leak it. Though unnamed, the attack matches the PowerSchool hack, which reportedly affected around 70 million individuals.

The hack exposed the personal data of over 60 million students and 9 million teachers; the breach became public in January.

In May, PowerSchool paid a ransom to avoid leaking stolen data and erasing it, but the attackers kept the data and began extorting school districts in the US and Canada. Court documents show Lane returned about $160,000 of the stolen $3 million.

The student was sentenced to four years in prison and three years of supervised release. The judge ordered him to pay $14 million in restitution plus a $25,000 fine.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, PowerSchool)







Source link

About Cybernoz

Security researcher and threat analyst with expertise in malware analysis and incident response.