PowerSchool hacker sentenced to 4 years in prison

A 19-year-old Massachusetts man who pleaded guilty to hacking the educational technology company PowerSchool was sentenced to four years in prison on Tuesday.

Matthew Lane, who demanded a ransom of $2.9 million from PowerSchool in exchange for not leaking personal data belonging to more than 70 million people, also was ordered to pay about $14 million in restitution and a $25,000 fine, according to court filings.

The hack and its aftermath cost PowerSchool more than $14 million, including the expense of identity theft monitoring for victims. Prosecutors had sought a seven-year sentence. 

Prosecutors told the judge that Lane acted out of greed and had a long history of hacking.

Personal data, including Social Security numbers, special education status and medical conditions for more than 60 million students and 9 million teachers, were exposed in the hack, which became public in January.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Suzanne Smalley

Suzanne Smalley

is a reporter covering privacy, disinformation and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop and Reuters. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.

 

Total
0
Shares
Previous Post

F5 Breach Exposes BIG-IP Source Code — Nation-State Hackers Behind Massive Intrusion

Next Post

Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months

Related Posts

Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions

Google on Wednesday released security updates for the Chrome web browser to address four vulnerabilities, including one that it said has been exploited in the wild. The zero-day vulnerability in question is CVE-2025-10585, which has been described as a type confusion issue in the V8 JavaScript and WebAssembly engine. Type confusion vulnerabilities can have severe consequences as they can be
Read More

Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hosts

Cloudflare on Wednesday said it detected and mitigated the largest ever distributed denial-of-service (DDoS) attack that measured at 29.7 terabits per second (Tbps). The activity, the web infrastructure and security company said, originated from a DDoS botnet-for-hire known as AISURU, which has been linked to a number of hyper-volumetric DDoS attacks over the past year. The attack lasted for 69
Read More