The year began at the school gate. On December 28, 2024, an intruder used a single compromised support credential to log into PowerSchool's customer support portal and export data from its Student Information System — the software that, for a vast share of North American schools, simply is the record of a child's education. PowerSchool began notifying affected districts on January 7, 2025. The forensic investigation placed the unauthorized access between December 19 and 28, and the scale was staggering: the attacker's extortion demand claimed data on roughly 62.4 million students and 9.5 million teachers — figures PowerSchool never confirmed as a precise count, but which went unchallenged as the incident came to be widely described as the largest breach of children's data in US history.
For a subset of those affected, the stolen fields went beyond names and grades to Social Security numbers, medical alerts, and home addresses — the kind of data a child cannot change and will carry for decades. PowerSchool paid the attacker's ransom (court documents later put the demand around $2.85 million in Bitcoin) in exchange for a promise the data would be deleted. It was, predictably, a promise made by a criminal: in May, individual districts including the Toronto District School Board began receiving fresh extortion emails built on the same stolen data. Paying had bought nothing but a receipt.
The through-line of the whole affair — one stolen password, one over-trusted support portal, tens of millions of the most vulnerable data subjects imaginable — was the year's opening thesis statement. 2025 would be a year about the fragility of the systems everyone depends on and no one quite owns, and it started with the one that holds our children's report cards.
Silk Typhoon named, sanctions land
January carried the fallout from the US Treasury's December 30 disclosure that a Chinese state actor had reached departmental workstations by abusing a stolen BeyondTrust remote-support API key. Reporting indicated the intruders had targeted the Office of Foreign Assets Control and the Committee on Foreign Investment in the US — the offices that run sanctions and screen foreign deals. The activity was attributed to the group tracked as Silk Typhoon, and on January 17, Treasury's OFAC sanctioned a Shanghai-based hacker linked to the intrusion, alongside a firm tied to the separate Salt Typhoon telecom-espionage campaign. A stolen vendor key had opened the US Treasury: the borrowed-credential problem, at the highest possible stakes.
Britain moves to ban ransoms
On January 14, the UK Home Office opened a consultation proposing to ban ransomware payments by public-sector bodies and critical national infrastructure operators, alongside a regime requiring other victims to notify authorities before paying, plus mandatory incident reporting. It made the UK one of the first major economies to formally float a targeted ransom-payment ban — an attempt to attack ransomware's business model at the source, by drying up the revenue. The debate it opened, over whether banning payment protects victims or punishes them, is one the world is still having.
The rulebook arrives (in draft)
On January 3, 2025, India's Ministry of Electronics and IT released the draft Digital Personal Data Protection Rules, 2025 for public consultation — the long-awaited operational machinery under the DPDP Act, 2023, covering consent notices, breach notification, obligations for significant data fiduciaries, and verifiable parental consent for children's data, with feedback open until February 18. It was the first concrete step in a year-long march that would end, in November, with the rules notified in force. The same month brought a cautionary counterpoint: the BASHE ransomware group claimed on its leak site to have breached ICICI Bank customer data, setting a January 24 ransom deadline. ICICI never confirmed a breach, and OSINT analysts found inconsistencies in the posted samples — so the claim stayed exactly that, a claim. Two Indian data stories to open the year: one a landmark of regulation, the other a reminder of how much noise surrounds every real signal.
⏳ Time capsule — January 2025
- TikTok went dark for US users for about 14 hours on January 18–19 as a divest-or-ban law took effect, returning after a pledged enforcement delay.
- On January 27, Chinese startup DeepSeek's R1 app topped the US App Store and Nvidia shed roughly $589 billion in value — the largest single-day market-cap loss in history at the time.
- On January 21, OpenAI, SoftBank, and Oracle announced Stargate, a US AI-infrastructure venture pitched at up to $500 billion.
- On January 16, Blue Origin's New Glenn reached orbit on its first flight, while SpaceX's Starship Flight 7 upper stage broke apart over the Caribbean.
Where the archive begins
This is, for now, the oldest edition in The Vault — the floor of the archive we've restored, and the start of a year whose every theme was already visible in January. The PowerSchool breach set the template for 2025's education and identity disasters, and its pay-and-get-re-extorted ending became the standard argument against ever trusting a criminal's promise. Silk Typhoon's stolen key foreshadowed a year defined by borrowed credentials. Britain's ransom-ban proposal opened a policy debate that only widened. And India's DPDP draft began the runway that would land in November's rulebook and 2026's compliance scramble. Below this month, The Vault's next restorations will reach back into 2024 and beyond — because the story didn't start here either. It never does.