School portal data leak: what parents should do after a school breach
Breach / exposure. Updated 2026-09-13. About 5 minutes to read.
Ask the school exactly which fields were exposed, change portal passwords for every parent and student account, and in the US freeze your child's credit if their Social Security number was included.
School systems hold some of the most complete records that exist about a child: legal name, date of birth, home address, parents' contact details, and sometimes medical notes, special education plans and Social Security numbers. That makes them a prime target. In the PowerSchool breach of December 2024, the US Department of Justice counted 62.4 million students and 9.5 million teachers across 6,505 school districts.
Children rarely notice identity theft until they apply for a loan, a job or a phone plan years later. The steps below help you find out what was exposed, block misuse of your child's identity and prepare your family for the scams that follow a school breach.
Recent school breaches and what they exposed
PowerSchool (December 2024): an attacker used credentials stolen from a subcontractor to get into PowerSchool's customer support portal on 19 December 2024 and downloaded school databases. Exposed data included names, addresses, phone numbers and parent details, and for some students Social Security numbers and medical information.
PowerSchool follow-up (May 2025): PowerSchool had paid a ransom, yet school districts in the US and Canada later received extortion demands containing samples of the stolen data. The hacker, Matthew Lane, was sentenced to four years in prison on 15 October 2025.
Victorian government schools (January 2026): a Department of Education database was accessed, exposing names, school email addresses, schools, year levels and encrypted passwords for more than 665,000 students. The department said dates of birth, phone numbers and home addresses were not accessed.
Canvas (May 2026): Instructure, the company behind the Canvas learning platform, confirmed names, email addresses, student ID numbers and user messages were exposed. The attackers claimed nearly 9,000 schools were affected, a figure Instructure did not confirm.
Paying a ransom did not make PowerSchool's data disappear. Plan as if exposed school data will be reused for years.
Why children's records are so valuable to criminals
In the US, a child's Social Security number usually has no credit history attached, so a criminal can build a fake identity on it and run up debt that goes unnoticed for a decade. Parents often find out when a teenager is refused a student loan or a first credit card.
Everywhere, school data makes scams convincing. A message that names your child's teacher, year level and school portal looks official. And for families in custody disputes or protective arrangements, an exposed home address is a safety issue before it is a privacy issue.
What to do this week
Read the notice from the school or district and write down which system was breached and which data fields it lists.
If free credit or identity monitoring is offered, enrol by typing the provider's web address yourself and using the code in the letter, never through a link in an email or text.
Change the password on every parent and student portal account, and on any other site where the same password was used.
Turn on two-factor authentication on the parent portal if it is offered.
Tell your children that the school will never ask for their password by message, and to show you any message that mentions their school details.
Ask the school whether Social Security numbers, medical notes or special education records were included. If they were, move on to a credit freeze.
Freeze your child's credit in the US
The FTC says that if your child is under 16 you can request a free credit freeze, which stays in place until you ask the bureaus to remove it. Teenagers who are 16 or 17 can request and remove a freeze themselves. The process for a minor is different from an adult's and usually needs documents rather than an online form.
Contact Equifax, Experian and TransUnion separately and follow each bureau's instructions for a minor's freeze.
Expect to provide proof of your identity, proof of address, and your child's birth certificate and Social Security card.
Keep the confirmation each bureau sends, and store any PIN in your password manager.
Watch for warning signs the FTC lists, such as calls about bills in your child's name or a notice that their Social Security number was used on another tax return.
If misuse has already happened, report it at IdentityTheft.gov and ask each bureau to remove the fraudulent accounts.
Australia, the UK and Canada: who to contact
Australia: government schools fall under state privacy laws and regulators, such as OVIC in Victoria and the Information and Privacy Commission in NSW. Many non-government schools are covered by the federal Privacy Act and the OAIC's Notifiable Data Breaches scheme. IDCARE offers free support on 1800 595 160.
Australia and the UK: children rarely have credit files, so focus on account passwords, phishing and physical safety rather than credit freezes.
United Kingdom: the school is responsible for your child's data. Raise concerns with the school's data protection officer first, then complain to the ICO. You can make a subject access request to see what the school holds.
Canada: provincial privacy commissioners investigated the PowerSchool breach, and regulators in Ontario and Alberta found school boards were not prepared. Complain to your provincial commissioner if your board does not answer.
The scams that follow a school breach
Texts or emails about overdue lunch balances, excursion fees or uniform orders with a payment link.
Messages that appear to come from a teacher or principal asking parents to log in to a new portal.
Fake compensation or class action sites that ask for your child's Social Security number or bank details.
Calls claiming your child is in trouble or hurt, using real names and school details to rush you into paying.
A school or district will not ask you to confirm your child's Social Security number, passwords or bank details by email or text after a breach. Call the school office on a number you already have.
Questions to ask the school
Which vendor or system was breached, and which fields about my child were in it?
Were Social Security numbers, medical information, disability or special education records included?
What monitoring or support is being offered, and until when?
How long does the school keep records of former students, and can old records be deleted?
Frequently asked questions
Only encrypted passwords were exposed. Do we still need to change them?
Yes. Encrypted or hashed passwords can sometimes be cracked, especially simple ones. Change the portal password and any account that used the same password.
Does my child need a credit freeze in Australia or the UK?
Usually not. Credit files are generally created when someone first applies for credit as an adult. Focus on passwords, phishing awareness and safety if your address was exposed.
Can I ask the school to delete my child's data?
You can ask. Schools must keep some records for set periods. Privacy laws in the UK and Australia expect organisations to delete or de-identify information they no longer need, so ask what the school's retention period is.
Teachers were affected too. What should staff do?
The same steps apply. Freeze your credit if your Social Security number was included, change passwords, and be alert to phishing that uses your school role to target parents or colleagues.