The reopening of schools and the return of students to their classrooms has been postponed in the city of Hartford, Connecticut, after a ransomware attack infected the city's IT network. According to a statement from the Hartford Public Schools, the ransomware attack affected many of its internal IT systems, causing an extended outage. Its IT staff is working to restore services, which takes time, resulting in a delay in the opening of schools, which was scheduled for September 8.

Hartford Mayor Luke Bronin said at a press conference this morning that the school district's network was breached on Sept. 3. The state capital was not aware of the attack until Sept. 5, when hackers deployed ransomware and began encrypting devices on the district's network. Because the attack affected not only classroom computers but also the system responsible for transporting students on school buses, the reopening of schools was postponed until the systems.
Bronin said no ransom, but even if it does, Hartford will not pay it. Additionally, the mayor said that while no ransom note was found, there was a text message installed on multiple systems that said a ransomware attack had occurred and asked local authorities to contact a specific email. However, Bronin clarified that they will not be contacting that email address, but will leave the matter to the authorities.

Bronin also noted that so far there is no evidence that any data, but they are looking into it further. In addition, a source said that Hermes ransomware is believed to be behind the attack, but these claims have not been confirmed at this time. Older versions of Hermes had a vulnerability that allowed free file recovery. This vulnerability has since been fixed, and the current attacks are not decryptable.
Since late 2019, ransomware gangs have been stealing unencrypted data, including student and employee files, before deploying ransomware across a network. Ransomware operators then use this data to convince victims to pay a ransom by threatening to share the files on leakage .

The Hermes ransomware operators are not known for stealing data before deploying their ransomware, but that doesn't mean they haven't started adopting this tactic. Since the threat actors gained access to the school district's systems for two days before deploying the ransomware, they had plenty of time to gather unencrypted files.
Last week, operators of the SunCrypt ransomware attacked a school district in North Carolina, USA, and leaked 5 GB of files containing student and employee data.

Finally, Hartford did not provide a clear timeline for the restoration of its IT systems, while it said it would notify parents when the school year begins.
