Comment It's worse than what's reported here.... (Score 1) 18
IT pro in K-12 education here...and former PS customer; we used to use Sungard Pentamantion's eSchoolPlus and eFinancePlus that were purchased by PS a while back. Support was and is still awful from what I read from other districts still using the products. Have migrated from both, but still on mailing lists for things as well as on a state IT Ed Tech mailing list. From what's been reported by affected districts, it was a remote access account credential that was compromised and used against a data exporting application. Stupid on so many levels...why the account uses the same password (presumably, haven't seen independent confirmation of that) for every customer is both lazy and vulnerable....which is why this happened. Affected both their cloud users and users still hosting their own application stacks.
Also from what affected districts have reported, it's not student SSN's compromised, those are not normally stored in SIS dbs. It was staff that were tied into the affected tables.