All public schools that use or have used PowerSchool’s student information system were affected “to some degree” by last month’s data breach, the state Department of Public Instruction confirmed to WRAL News on Tuesday,

At least some teachers’ and students’ Social Security numbers were exposed. DPI hasn’t released how many but did say fewer than 1,000 students’ Social Security numbers were in the data. More teachers’ Social Security numbers were exposed than students’, department spokeswoman Jeanie McDowell said.

Other WRAL Top Stories

But who exactly was affected and what data was exposed is still unclear.

McDowell said PowerSchool is still analyzing the data and plans to begin notifying affected people by the end of the month.

“NCDPI is working closely with [public schools] across the state to identify the specific information accessed at each school and to support students and staff throughout this process,” McDowell wrote in a statement to WRAL News. “We are also advocating with PowerSchool on behalf of North Carolina’s students and educators to ensure timely notification and appropriate actions, such as credit monitoring. NCDPI remains committed to providing guidance and resources to help affected individuals stay informed and receive the necessary support as we work to address the impact of this incident.”

PowerSchool says law enforcement officials are monitoring the dark web for the data collected by the hackers. The company also plans to offer free credit monitoring to anyone affected by the breach.

PowerSchool has said the data collected by the hackers has been destroyed and won’t be shared, and DPI and school systems have repeated that claim. But cybersecurity experts have warned people to watch out for the data appearing online and to take advantage of any credit monitoring offered.

Cumberland County Schools confirmed it was affected by the PowerSchool data breach, in a message sent to families Monday.

Officials said the system is still working with PowerSchool and DPI to determine which individuals were affected and “the full scope of the breach.”

District officials said in the message that they were notified over the weekend that they were affected.

“Our district is working closely with NCDPI and PowerSchool to notify impacted individuals once the full scope of the breach is confirmed,” the system’s message states. “We remain committed to protecting the data of our students and staff and will continue to provide updates as more information becomes available.”

The breach occurred within PowerSchool's software, which has student data contracts with government agencies across the globe.

While the state contracts with PowerSchool for its statewide student information system, it doesn’t have access to software’s maintenance tunnel that was used by the unauthorized parties who accessed and exported data from two of the software system’s tables.

By July, all public schools will transition to using Infinite Campus instead of PowerSchool —  a decision made by the State Board of Education in November 2023, long before the Dec. 19, 2024, cybersecurity breach.

Some school systems and charter schools are already using Infinite Campus but may have had historical data in the PowerSchool system.