All field notes

Field note · Incident study

The Court Just Priced Pre-Close Control

On March 18, 2026, a federal judge in the Southern District of California allowed a consolidated class action against Bain Capitalto proceed on multiple counts arising from the PowerSchool data breach — a breach that started before Bain’s $5.6 billion acquisition of PowerSchool closed. It is, per Womble Bond Dickinson, the first ruling of its kind against a private equity firm for a portfolio company’s data breach.

The interesting part is why the ruling held. It didn’t pierce the corporate veil in the traditional sense. It found that Bain had exercised operational control over PowerSchool’s cybersecurity decisions both before and after close, and that the contractual “disclaimer of control” language in the deal documents “does not compel a different result at this stage.” Control-in-fact ate control-on-paper. That’s the shift.

$5.6BBain acquisition of PowerSchool, closed Oct 1 2024
70MStudent + teacher records compromised (SSNs, medical, custody)
5Legal theories the court allowed to proceed against Bain
0Contractual disclaimers that held at motion-to-dismiss

The timeline

Six moments, in order. The first four are the exposure. The last two are the reckoning.

01

August 2024 — the breach starts, pre-close

A threat actor gains access to PowerSchool’s systems using stolen vendor credentials. The deal is negotiated, not closed. Bain is not yet the owner. The exposure is accumulating inside a company Bain has already agreed to buy.

Stolen vendor credentialsPre-close breach entry
02

September 2024 — the offer, conditioned

Bain’s offer includes veto rights over PowerSchool capital expenditures above $5M and over material vendor contracts. The offer is conditioned on cost-reduction measures, including layoffs of domestic cybersecurity staff. Bain has not closed the deal. It is nevertheless directing PowerSchool’s cybersecurity budget and headcount.

Pre-close veto rightsCyber staff cost cutsConditioned offer
03

October 1, 2024 — deal closes, board replaced

Bain replaces PowerSchool’s entire board immediately at close. It directs layoffs of at least 5% of the workforce, including “critical domestic IT staff.” It directs offshoring of cybersecurity, engineering, and IT functions to contractors using tools the plaintiffs later describe as “enabling vendors to bypass consent protocols.” The threat actor still has access.

Board replacementOffshored cyber opsConsent-bypass tooling
04

December 28, 2024 — ShinyHackers demands ransom

The ransom demand is how PowerSchool learns about the breach. A threat actor group calling itself ShinyHackers has been inside for four months. Public disclosure lands January 7, 2025. Data exfiltrated: names, SSNs, medical information, addresses, disability records, custody records. Roughly 60 million students and 10 million teachers across K-12 school districts.

Four-month dwell time70M recordsK-12 nationwide
05

2025 — class actions consolidate, name Bain

Multiple class actions are filed, consolidated in the Southern District of California. Both PowerSchool and Bain Capital are named as defendants. Bain moves to dismiss, arguing that its role was that of investor, not operator, and that the contractual language of the acquisition explicitly disclaimed operational control over PowerSchool.

Class consolidationBain motion to dismiss
06

March 18, 2026 — the court says no

The court grants Bain’s motion in part and denies it in part. Claims allowed to proceed against Bain: aiding and abetting, negligence, negligence per se, unjust enrichment, and violations of California’s Unfair Competition Law. The court finds the plaintiffs “sufficiently alleged that Bain exercised control over PowerSchool’s key strategic decisions — including cybersecurity operations, workforce decisions, and capital expenditures — both before and after the merger closed.” On the contractual disclaimer of control, the court is unimpressed: it “does not compel a different result at this stage.”

MTD partially deniedPre-close control = liabilityDisclaimer doesn’t hold

What just changed

What the market assumed pre-close control cost you, and what the court just ruled it costs you.

What contractual disclaimers protectedAssumption: SHIELDED
“Investor, not operator” language.Standard acquisition-document boilerplate disclaiming day-to-day control was assumed to hold at the pleadings stage.
Pre-close veto rights.Blocking capital-expenditure or vendor decisions above a threshold was treated as protective-only, not affirmative control.
Conditioning the offer on cost measures.Making the deal contingent on specific budget cuts was treated as negotiation, not direction.
Post-close operational directives.Board replacement, layoffs, and offshoring decisions were understood as legitimate owner activity, insulated from tort liability for downstream operational failures.
What actual operational control triggersRuling: LIABILITY
Control-in-fact eats control-on-paper.If you actually directed cybersecurity, workforce, and capital decisions, the contractual disclaimer language does not compel dismissal at the pleadings stage.
Pre-close conduct counts.What you did during negotiation, including how you conditioned your offer and what veto rights you exercised, can be pulled into the liability calculus.
Cost-reduction directives on cyber staff are exhibit A.Conditioning the offer on layoffs of “critical domestic IT staff” is now a discoverable pattern that plaintiffs will subpoena and courts will consider.
Aiding-and-abetting is on the table.Not just direct negligence. If you directed operational choices that enabled a breach to continue or amplify, you can be named alongside the portfolio company.

Control-in-fact ate control-on-paper.

The precedent shift — contractual disclaimers of control no longer end the analysis when the operational record contradicts them.

What Cyber Cost of Deal would and wouldn’t have changed

CCOD is a pricing framework. It doesn’t stop the ruling and it doesn’t undo the breach. What it does is put a defensible dollar figure on the liability slice the Bain ruling just created, so the deal team can price it before signing.

×What it wouldn’t have fixed
The court’s ruling.

The March 18 decision is the court applying tort doctrine to the facts as pleaded. No pricing framework changes what a judge decides at motion-to-dismiss on facts that already exist.

PowerSchool’s actual breach.

Stolen vendor credentials, four-month dwell time, K-12 data exfiltration. The operational incident is the operational incident. A diligence framework doesn’t rewrite what happened after the deal closed.

Bain’s specific offshoring decisions.

Post-close operational choices about vendor tools and cyber-staff geography are business decisions. CCOD prices the downstream expected loss; it doesn’t make the decision.

✓What it would have materially changed
Pricing the pre-close-control liability as its own line.

The moment the acquirer starts exercising veto rights, conditioning offers on operational changes, or directing headcount, a new liability line opens in the CCOD math. “If we condition the offer on cyber-staff reductions and the target is later breached in a way that traces to those reductions, expected loss on our balance sheet is $X.” That’s a number the deal team can weigh against the operational upside they were chasing.

Extending the exposure calculation past the closing.

Post-close directives that touch cybersecurity get priced against the expected class-action liability they invite. Offshoring cyber ops has a business case; it also has an expected legal-exposure cost. Both belong in the model.

Turning “we’re protected by the disclaimer” into a testable claim.

Every acquisition document has a control disclaimer. Not every acquirer’s conduct actually matches it. CCOD surfaces the gap by asking, in dollars, what happens if the disclaimer doesn’t hold. Bain just showed the market what that gap costs when a court decides to look through the paperwork.

Our read

Three things we think this ruling makes true, in order of confidence.

One. This is not one-off. It’s a template. The plaintiffs’ bar has been looking for a case like this for a decade. Now they have one, and it survived Bain’s motion to dismiss with five separate claims intact. Every other active PE firm with a breached portfolio company in the last three years is going to see a copycat filing test the same theory. The “shell holding company” defense is going to erode further with each ruling that follows the Bain court’s reasoning.

Two. The M&A cyber DD workflow now includes a pre-close-conduct audit. Not just “is the target secure.” Also: what has the acquirer already done to the deal that could look like operational direction on discovery? The offer letter, the term sheet, the negotiation record, the diligence memo instructions to counsel: everything from LOI through IC is now discoverable evidence in a potential class action against the acquirer.

Three. Cyber diligence has to price the legal exposure alongside the operational exposure. Traditional CCOD math priced the operational breach cost. The Bain ruling adds a new slice: the expected class-action liability that attaches to the acquirer when the acquirer’s own conduct is in scope. We’ve built a PE Cyber Liability Kit for the M&A and PE attorney bench that walks through this math, along with a pre-close control tripwire checklist and a post-close directive review flow. The kit exists because the previous version of the diligence workflow didn’t have language for what the court just made a live question.

If you’re running M&A cyber diligence on the buy side and want to see what pricing the acquirer’s own conduct looks like as a delivered artifact, that conversation starts on the vCISO Lite Cyber Cost of Deal page.

Primary sources