Matthew Lane, a Massachusetts student, pleaded guilty and was later sentenced in a federal case tied to the breach of education software provider PowerSchool, an intrusion U.S. authorities described as the largest cyberattack in U.S. education history. Prosecutors said Lane used stolen contractor credentials and vulnerability-scanning tools to access the company’s network, then threatened to publish sensitive records unless he was paid about $2.85 million in Bitcoin. The compromised data reportedly covered roughly 60 million students and 10 million teachers, including names, phone numbers, addresses, Social Security numbers and, in some cases, medical information.
Authorities said Lane also extorted a separate telecommunications company for $200,000 by threatening to release customer data. The case triggered ransom payments and White House Situation Room briefings, and investigators later found that some stolen PowerSchool data was allegedly retained by another actor and reused in follow-on extortion attempts against school districts. Lane received a four-year federal prison sentence and was ordered to pay more than $14 million in restitution, while U.S. investigators continue pursuing alleged co-conspirators.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By April 2026, Lane had pleaded guilty and received a four-year federal prison sentence for his role in the PowerSchool breach. He was also ordered to pay more than $14 million in restitution, while investigators continued pursuing alleged co-conspirators.
The U.S. Attorney's Office for the District of Massachusetts announced that Matthew Lane would plead guilty to charges tied to the theft and extortion of data from PowerSchool and a separate telecommunications company. The charges included cyber extortion conspiracy, cyber extortion, unauthorized access to protected computers, and aggravated identity theft.
After Lane's arrest, some of the stolen PowerSchool data was allegedly kept by a rogue actor and later used in additional extortion attempts against school districts. This indicated the breach continued to create downstream risk beyond the initial intrusion.
After accessing PowerSchool, Lane and co-conspirators allegedly threatened to release data belonging to about 60 million students and 10 million teachers unless they were paid roughly $2.85 million in Bitcoin. The stolen information reportedly included names, phone numbers, Social Security numbers, addresses, and medical histories.
Prosecutors said Matthew Lane used stolen login credentials to access the network of a software and cloud storage provider serving school systems, identified by reporting as PowerSchool. The intrusion exposed highly sensitive student and teacher data held by a provider used by much of North American K-12 education.
ABC News reported that the PowerSchool breach prompted ransom payments following the theft of education records. The incident was serious enough to trigger White House Situation Room briefings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
abcnews.com
Open sourceapnews.com
Open sourceinfosecurity-magazine.com
Open sourcejustice.gov
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.