
A 19-year-old college student from Worcester, Massachusetts, has agreed to plead guilty to a massive cyberattack on PowerSchool that extorted millions of dollars in exchange for not leaking the personal data of millions of students and teachers.
According to the U.S. Department of Justice, Matthew D. Lane pleaded guilty to four federal charges of one count each of cyber extortion conspiracy, cyber extortion, unauthorized access to protected computers, and aggravated identity theft.
The DOJ and court documents state that Lane and his conspirators breached a US-based telecommunications company in 2022, where they stole confidential customer information. After attempting to extort the telecom firm, the DOJ says they conducted an attack on an education company that would pay a ransom.
"On or about May 14, 2024, LANE messaged CC-1 that if Victim 1 did not pay the ransom, LANE and CC-1 could sell the Stolen Victim 1 Data. LANE further suggested, 'we need to hack another . . . company that[']ll pay'," reads the DOJ complaint.
While the complaint does not explicitly mention PowerSchool, sources told BleepingComputer that they are the education company referred to by the DOJ.
The threat actor used compromised credentials belonging to a PowerSchool contractor to breach the company and steal data for millions of students and faculty in December 2024.
As previously reported by BleepingComputer, threat actors breached PowerSchool's support platform, PowerSource, and used a maintenance tool to download the school's databases. These databases included the personal information of 62.4 million students and 9.5 million teachers from 6,505 school districts in the US, Canada, and other countries.
This data consisted of different information depending on the district, including students' and faculty's full names, physical addresses, phone numbers, passwords, parent information, contact details, Social Security numbers, medical data, and grades.
The DOJ says that PowerSchool received a ransom demand for approximately $2.85 million in Bitcoin on December 28, 2024. The threat warned that if payment was not made, the stolen data would be leaked "worldwide."
While BleepingComputer previously reported that PowerSchool paid a ransom demand to prevent the leak of data, it is still unclear how much was paid.
However, even after PowerSchool paid the ransom, the threat actors attempted to individually extort impacted school districts into paying further ransoms not to leak student data.
According to school notices and DataBreaches.net, these ransom demands claimed to be from Shiny Hunters, a prolific group of threat actors known for a wide range of breaches, including the SnowFlake data theft attacks and a 2022 data breach at AT&T that impacted 109 million people.
While many of the threat actors involved in the SnowFlake and AT&T attacks have been arrested over the past year [1, 2, 3], it's possible that other members carried out the attacks, or that copycats are attempting to plant a false flag
In addition to the PowerSchool breach, Lane also faces charges for the attempt to extort the U.S.-based telecommunications company, where they demanded a $200,000 ransom and made threats against company executives if the ransom was not paid.
Lane has agreed to plead guilty to all four counts and faces a mandatory minimum sentence of two years for identity theft and up to five years on each of the other charges.
Update 5/23/25: Updated story to correct that the PowerSchool credentials were not stolen during the breach of the US telecommunications company.
Break down IAM silos like Bitpanda, KnowBe4, and PathAI
Broken IAM isn't just an IT problem - the impact ripples across your whole business.
This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what "good" IAM looks like, and a simple checklist for building a scalable strategy.





Comments
Ellie_Cat - 7 months ago
My school uses this. Kinda creepy how my info may be leaked somewhere
SteveSarginson - 7 months ago
There has been a recent round of extortion attempts on Powerschool customers. Is there any connection to Matthew Lane? Are these rounds of extortion people who actually have access to the data?
Elastoer - 7 months ago
I work in I.T. Support. I'm often called to clean up the messes that these cretins leave behind. I hope his time in prison teaches him something worthwhile.
deltasierra - 7 months ago
(Office Space movie reference) Hopefully some time in a federal pound-me-in-the-*** prison will teach him some things yes. :P
deltasierra - 7 months ago
Sad lose-lose situation. Too bad more of these black hats don't focus their talents and skills for good as white hats. Cybersecurity is a broad, well-paying, and in-demand field in the U.S. and many other developed countries.