91制片厂视频

Privacy & Security

COVID-19 and Cybersecurity: 鈥楥atastrophic Attack on Our Technology Systems鈥

By Mark Lieberman 鈥 December 01, 2020 7 min read
BRIC ARCHIVE
  • Save to favorites
  • Print
Email Copy URL

Two large school districts have been rattled in the last week by incidents related to internet security and privacy, as vulnerability to cyberattacks remains high during the current pandemic-era period of increased technology use.

In Baltimore County, Md., classes shut down the day before Thanksgiving due to what school officials a 鈥渃atastrophic attack on our technology systems.鈥 Schools remained closed Monday and Tuesday and are expected to reopen Wednesday. The district had been in fully remote learning mode that will last at least into January.

Meanwhile, in Chicago, parents and elementary school students were alarmed over this weekend when they received a series of unsavory, profanity-laced emails in their school inboxes during a 90-minute period in the morning. According to a , the initial message read, 鈥淚 do not know who I am. I do not know why I am here. All I know is that I must kill,鈥 and was followed by a series of replies that included question marks and vulgar language.

The incidents are different and unrelated. Baltimore County district officials have confirmed that the hack was a ransomware attack. District officials have been circumspect so far about the nature and extent of the breach, and whether sensitive data has been compromised or made public.

The Chicago incident, by contrast, 鈥渄id not pose an information security risk or permit access to anyone outside the CPS network,鈥 according to a statement from the district. A districtwide email group had inadvertently been set to allow anyone to respond to the entire group, the statement said. The district has not shared further details about the source of the messages.

These two incidents are the latest in a growing pile of reports from districts experiencing cybersecurity challenges this school year.

In Toledo, Ohio, district officials confirmed in early November that a ransomware attack had taken place in September after months of speculation among community members. That attack resulted in the dissemination of student and staff data, school officials said in a .

Some districts have yet to confirm apparent cyberattacks. The New Haven district in Connecticut was last month to determine the extent of an apparent attack on middle school students鈥 email accounts. The Norfolk district in Virginia as a preemptive measure after a district official noticed possible disturbances on the network.

The threats also extend to education companies. Stride, the for-profit education provider previously known as K12 Inc., that it is paying ransom to cybercriminals who recently invaded its network and is working with a third-party provider to determine the extent of the hack. A found that cyberattacks on education companies, while rare, can be serious because they can affect students across numerous districts.

Schools are among the institutions most likely to be targeted by hackers during this current period of heightened attention on cybersecurity threats, said Richard DeMillo, interim chair of the School of Cybersecurity and Privacy at the Georgia Institute of Technology. Public institutions that have a strong motivation to protect their data are always at a higher risk, and the pandemic has increased that risk because far more school activity is occurring using digital tools.

鈥淚t鈥檚 not that the threats are changing, it鈥檚 that the risks are growing,鈥 DeMillo said. 鈥淵ou should assume the more you鈥檙e doing online, the more the risks have gone up, the more serious the consequences would be if there were a serious breach.鈥

See Also

The Federal Bureau of Investigation alerted K-12 schools earlier this year that ransomware attacks on the rise, and has been assisting districts including Baltimore County when cybersecurity breaches crop up. The superintendent of the Hartford school district in Connecticut is among the scheduled speakers at a on the topic of cybersecurity threats facing state and local governments.

The Consortium for School Networking (CoSN), a membership organization that represents school IT leaders, has been advocating even prior to the pandemic for the Federal Communications Commission to allow funds from its E-Rate program for school connectivity to go towards strengthening cybersecurity protections. Districts have reported spending anywhere from $25,000 to $150,000 a year for basic firewall protections alone, according to a .

The recent spate of cybersecurity incidents affecting major districts only reinforces the urgency of those funds, said Keith Krueger, CEO of CoSN. He believes ongoing discussions about closing the digital divide need to more strongly touch on cybersecurity as a key component.

鈥淛ust getting devices and broadband connectivity, Wi-Fi, that alone is insufficient if the network isn鈥檛 usable, isn鈥檛 safe and secure,鈥 he said.

Understanding the Risks

Sean Gallagher, a senior threat researcher for the technology security firm Sophos, worked prior to this February as a journalist for the technology publication Ars Technica. In that capacity, he was researching Baltimore school networks last year in the aftermath of a ransomware attack on the Baltimore city school district, which is separate from the county district.

Using a search engine that detects cybersecurity vulnerabilities, he found that Baltimore County鈥檚 network protections hadn鈥檛 been updated to protect against one of the possible culprits of the Baltimore City attack.

Gallagher said in an interview he contacted the district at the time to flag those concerns, but never heard back. A district spokesperson didn鈥檛 respond to a request for comment.

A released just one day before Baltimore County schools closed last week reinforced Gallagher鈥檚 findings, identifying 鈥渟ignificant risks鈥 within the district鈥檚 network.

There鈥檚 not enough public information yet to determine whether the vulnerabilities identified in Gallagher鈥檚 2019 research or the 2020 state audit played a role in the current breach. But Gallagher said the series of events illustrates the importance of schools prioritizing cybersecurity efforts, and governments prioritizing funding for those efforts.

鈥淭hey really need to look at how they鈥檙e doing remote access, and take a really deep look at how their networks are connected to allow people to get in,鈥 he said.

In a survey conducted by the EdWeek Research Center in November, only 16 percent of teachers, principals, and district leaders said their school or district is engaged in full-time in-person learning. That means all the remaining districts have at least some remote learning currently taking place.

The more that schools have typically in-person activity happening on digital devices, the higher the risk becomes for a cybersecurity breach, according to DeMillo.

鈥淪taring at a computer screen in the privacy of your own home has now become a fairly public activity,鈥 DeMillo said. 鈥淭he level of hygiene it takes in order to keep that safe has to grow accordingly. That鈥檚 not a natural thing for a teacher to think about.鈥

How to Strengthen Protections

In the near term, experts said schools need to focus on raising awareness among employees of cybersecurity threats, and the role that their own activity could play in facilitating them.

Several Baltimore County teachers have shared on social media that their files have a Ryuk extension on them, according to a . The district has not confirmed that the breach was a Ryuk attack.

Regardless, the nature of Ryuk attacks is instructive, Gallagher said. They typically happen as a result of a single user clicking on an email message that contains an attachment or link. Clicking that link activates malware that can quickly spread to the whole system.

Most people are aware to some extent that cybersecurity is an issue, but getting them to follow through on that awareness with action can be much trickier, DeMillo said. Constantly reinforcing to administrators and teachers the importance of diligence is crucial, he said.

Schools also need to have policies and procedures in place for sharing the right amount of details of a hack that鈥檚 taken place.

鈥淓specially when you鈥檙e in the middle of a problem, you can鈥檛 always say everything publicly or you鈥檒l create a worse problem,鈥 Krueger said.

Fewer than 20 percent of school districts have a dedicated employee whose sole focus is cybersecurity, according to a 2020 survey of CoSN members. IT officials were stretched thin for tackling these issues even before COVID-19 and widespread digital learning.

鈥淭his isn鈥檛 something the average teacher or principal can handle. These are sophisticated cybercriminals targeting K-12,鈥 Krueger said. 鈥淚t鈥檚 just getting harder and harder.鈥

A version of this news article first appeared in the Digital 91制片厂视频 blog.

Events

Recruitment & Retention Webinar Keep Talented Teachers and Improve Student Outcomes
Keep talented teachers and unlock student success with strategic planning based on insights from Apple 91制片厂视频 and educational leaders.鈥
This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of 91制片厂视频 Week's editorial staff.
Sponsor
Families & the Community Webinar
Family Engagement: The Foundation for a Strong School Year
Learn how family engagement promotes student success with insights from National PTA, AASA鈥痑nd leading districts and schools.鈥
This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of 91制片厂视频 Week's editorial staff.
Sponsor
Special 91制片厂视频 Webinar
How Early Adopters of Remote Therapy are Improving IEPs
Learn how schools are using remote therapy to improve IEP compliance & scalability while delivering outcomes comparable to onsite providers.
Content provided by 

EdWeek Top School Jobs

Teacher Jobs
Search over ten thousand teaching jobs nationwide 鈥 elementary, middle, high school and more.
Principal Jobs
Find hundreds of jobs for principals, assistant principals, and other school leadership roles.
Administrator Jobs
Over a thousand district-level jobs: superintendents, directors, more.
Support Staff Jobs
Search thousands of jobs, from paraprofessionals to counselors and more.

Read Next

Privacy & Security Download A Tip Sheet to Help Teachers Prevent and Respond to Doxxing
Teachers can be a target for malicious actors. Use this tip sheet to prevent and respond to doxxing.
1 min read
Image of digital safety against doxxing and privacy invasion.
Laura Baker/91制片厂视频 Week via Canva
This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of 91制片厂视频 Week's editorial staff.
Sponsor
Privacy & Security Quiz
Quiz Yourself: How Much Do You Know About Cybersecurity For Schools And Districts?
Answer 6 questions about actionable cybersecurity solutions.
Content provided by 
Privacy & Security What Schools Need to Know About These Federal Data-Privacy Bills
Congress is considering at least three data-privacy bills that could have big implications for schools.
5 min read
Photo illustration of a key on a digital background of zeros and ones.
E+
Privacy & Security A New Federal Taskforce Targets Cybersecurity in Schools
The 鈥済overnment coordinating council" aims to provide training, policies, and best practices.
3 min read
Illustration of computer and lock.
iStock / Getty Images Plus