Data breaches had not slowed in 2025. Ransomware payouts were at a high. Artificial intelligence was making malware faster and harder to stop, and the average data breach was costing over $5 million.
PowerSchool
PowerSchool, a cloud education-software company, was breached on December 28, 2024, and disclosed it on January 7, 2025. More than 70 million people were affected, including 62.4 million students and 9.5 million teachers.
Attackers used stolen login credentials to reach the PowerSIS system and take personal data. What was stolen:
- Grades
- Medical records
- Social Security numbers
- Other personally identifiable information
PowerSchool offered two years of identity-theft protection and credit monitoring to the people affected. That is a first step after the fact. If you receive a breach notice:
- Change compromised passwords immediately, especially where the same password was reused.
- Turn on two-factor authentication where you can.
- Use a password manager, such as Bitwarden or 1Password, for a strong, unique login on every site.
WhatsApp spyware that needed no click
In early 2025, Meta disclosed a zero-click spyware attack on high-risk WhatsApp users. The tool was Graphite, made by Israel-based Paragon Solutions. About 90 people were targeted, mostly journalists, activists, and civil-society leaders.
A zero-click attack does not need the victim to tap a link or open a file. Graphite gave attackers access to:
- Encrypted messages
- Microphones and phone calls
- Real-time location
Meta sent Paragon Solutions a cease-and-desist and was considering further legal action. What to do, with the caveat that a person cannot fully stop a zero-click exploit alone:
- Keep apps and the operating system updated, because patches often close these holes.
- Do not download unknown files or tap random texts.
- Signal is an app that is regularly audited for privacy and security.
Defense credentials for sale
In early 2025, hundreds of logins tied to U.S. Department of Defense personnel were found for sale on the dark web. That kind of access could let an attacker or a nation-state reach sensitive networks, skip internal controls, or phish further inside government systems.
Arctic Wolf: credential-based attacks rose 442 percent in late 2024. Weak, reused, or stolen passwords are often the easy way in. For an organization:
- Require a unique password and multi-factor authentication on every account.
- Audit who has access.
- Watch the dark web for leaked credentials with a service such as Have I Been Pwned, or with an enterprise tool.
What to take from the three
- Logins are what attackers want. Treat them as the keys to the business.
- A faster response after a breach leads to a better outcome.
- Updates, multi-factor authentication, and monitoring do more than cleaning up afterward.
- Managed IT security services can help a small business defend against breaches and other threats.
