The Old Guardian
Long before a provincial supervisor walked into TDSB headquarters, the board’s own systems were already failing the people they were supposed to protect. Ontario’s privacy watchdog has now said so directly.
What Happened
In December 2024, hackers breached PowerSchool, the vendor TDSB and thousands of other school districts across North America relied on to store student information. By January, TDSB confirmed the scope for its own students: roughly 1.49 million current and former students had addresses, health card numbers, emergency contacts, and in some cases medical information exposed. Some of the records dated back decades.
PowerSchool paid the hackers to delete the stolen data. It didn’t work. In May, the same attacker came back, this time demanding ransom directly from the affected school boards using data from the original breach.
This wasn’t TDSB’s only cybersecurity failure that year. A separate 2024 breach hit a test environment the board was using, one that, against basic security practice, contained real production data instead of synthetic test data. Roughly 280,000 students and staff had their information exposed through that incident alone. Then in 2025, a social engineering attack compromised a vice-principal’s login credentials, giving an outside actor access to systems across several schools.
The Regulator’s Verdict
Ontario’s Information and Privacy Commissioner investigated. In November 2025, the office found that TDSB and other GTA boards did not have “reasonable measures” in place to prevent the breach, pointing specifically to insufficient oversight of the vendor entrusted with the data in the first place.
That’s not a hacker outsmarting a well-defended system. That’s a regulator concluding the defence wasn’t adequate to begin with.
Why This Belongs in the Supervision Conversation
Every one of these incidents happened before the province placed TDSB under supervision. The board’s defenders, and this outlet has made the same point, have argued that supervision was justified by a real, documented pattern of governance failure: no long-term capital plan, the worst facility conditions in the province, safety incidents underreported to the Ministry. Add vendor oversight to that list. A board responsible for the personal information of 1.49 million students didn’t have the controls in place to protect it, and needed a regulator to say so before anything changed.
None of that means everything that has happened since supervision began is justified by it. Those are separate questions, and this outlet has been careful to keep them separate. But anyone arguing TDSB’s pre-supervision record was fine, or that the Ministry’s intervention had no real basis, has to explain this file too.
Where TDSB Actually Fell Short, and Where It Didn’t
TDSB’s own letters to families tell a different story than the one that might seem obvious here, and it’s worth getting the distinction right. PowerSchool notified the board on January 7, 2025. TDSB sent a preliminary letter to families the very next day. By January 20, a far more detailed follow-up, signed by then-Interim Director of Education Stacey Zucker, laid out exactly which categories of data were exposed, broken down by date range, down to the specific detail that Social Insurance Numbers and financial information were never stored in the system and were never at risk. In May, a third letter, this one signed by Clayton La Touche, informed families that the ransom PowerSchool paid to have the stolen data deleted had failed, and that a threat actor was now using the same data to demand payment directly from school boards.
That’s a fast, specific, repeatedly updated communication record. Whatever else TDSB got wrong here, keeping families informed once the breach was discovered isn’t it.
The failure the IPC identified sits earlier in the chain. Notifying people quickly after a breach is not the same as having the vendor oversight to prevent one. TDSB handled the aftermath of this incident about as well as an aftermath can be handled. The question that actually matters, the one the Commissioner answered, is why a board responsible for 1.49 million people’s personal information didn’t have controls in place strong enough to stop the breach from happening at all.
Sources: CBC News, Global News, CP24, the Office of the Information and Privacy Commissioner of Ontario, and TDSB’s public letters to families dated January 8, January 20, and May 7, 2025.

