Summary:
1. A 19-year-old college student is pleading guilty to carrying out a massive hack against PowerSchool, a popular student information system.
2. The attack involved cyber extortion, unauthorized access to protected computers, and aggravated identity theft.
3. The hacker threatened to leak personal information of millions of students and teachers if a ransom was not paid.
Article:
College Student to Plead Guilty in PowerSchool Hack
A 19-year-old college student from Massachusetts has agreed to plead guilty to charges related to a major hack against PowerSchool, a widely used student information system. The Department of Justice announced that Matthew Lane will plead guilty to cyber extortion, unauthorized access to protected computers, and aggravated identity theft.
Details of the Attack
Although PowerSchool was not explicitly named by the DOJ, the specifics of the attack align with the incident. The hacker threatened to release sensitive information, including names, email addresses, Social Security numbers, and medical data of millions of students and teachers unless a $2.85 million ransom was paid. It was later confirmed that PowerSchool was the target of the breach.
Response from PowerSchool
In response to the data breach, PowerSchool acknowledged the unauthorized extraction of personal information from its customer support portal. The company ultimately paid the ransom to prevent the hacker from disclosing the stolen data. However, additional threats were made to expose the information, leading to concerns about the security of the compromised data.
Legal Charges Against the Hacker
The DOJ alleges that Lane gained access to PowerSchool using stolen login credentials and transferred the data to a server in Ukraine. Additionally, Lane faces charges for breaching and extorting another undisclosed US-based telecommunications company. US Attorney Leah Foley condemned Lane’s actions, emphasizing the impact on children, teachers, and parents affected by the breach.
Overall, the case highlights the serious consequences of cybercrimes and the importance of safeguarding sensitive information in the digital age.