PowerSchool hacker got four years in prison
麻省学生Matthew D. Lane因黑客攻击PowerSchool等公司并勒索300万美元被判4年徒刑。其窃取师生数据并威胁泄露以索要赎金,导致超7000万人受影响。法院责令其赔偿1400万美元并支付2.5万美元罚款。 2025-10-17 08:59:12 Author: securityaffairs.com(查看原文) 阅读量:7 收藏

PowerSchool hacker got four years in prison

Matthew D. Lane, a Massachusetts student, got four years in prison for hacking and extorting $3M from PowerSchool and another company.

A Massachusetts student, Matthew D. Lane, was sentenced to four years in prison for hacking and extorting about $3 million from two companies, including PowerSchool.

In May, Lane pleaded guilty to hacking two U.S. companies, including likely PowerSchool, and extorting them.

The student used stolen credentials to access a company serving schools in the US, Canada, and beyond, hacking its network in September and December 2024. He exfiltrated student and teacher data (including names, addresses, birth dates, emails, Social Security numbers, and medical info) and demanded $2.85 million in Bitcoin, threatening to leak it. Though unnamed, the attack matches the PowerSchool hack, which reportedly affected around 70 million individuals.

The hack exposed the personal data of over 60 million students and 9 million teachers; the breach became public in January.

In May, PowerSchool paid a ransom to avoid leaking stolen data and erasing it, but the attackers kept the data and began extorting school districts in the US and Canada. Court documents show Lane returned about $160,000 of the stolen $3 million.

The student was sentenced to four years in prison and three years of supervised release. The judge ordered him to pay $14 million in restitution plus a $25,000 fine.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, PowerSchool)




文章来源: https://securityaffairs.com/183515/security/powerschool-hacker-got-four-years-in-prison.html
如有侵权请联系:admin#unsafe.sh