
Fairfax County Public Schools (FCPS), the 10th largest school system in the U.S., has been hit by ransomware. The school system is also the largest in the Baltimore-Washington metropolitan area. It has more than 188,000 students and approximately 25,000 employees working in 198 schools and centers in Virginia.
The FBI participated in the investigation into the ransomware attack
The exact date of the ransomware attack has not been revealed , but FCPS said it is working with the to FBI find the ransomware gang behind the incident.
"We recently learned that ransomware was placed on some of our technology systems. We take this matter very seriously and are working to address the issue," the Fairfax County Public Schools statement said.
The school complex also said it believes the perpetrators of the attack are a group that has been linked to dozens of attacks ransomware on other school systems and companies.
FCPS also requested the assistance of "external" security to conduct the investigation and restore the systems affected by the attack.
“FCPS is committed to protecting the information of our students, staff, and their families,” the school district added. “We will cooperate with law enforcement to the fullest extent possible to prosecute individuals or groups who attack our systems.”
BleepingComputer attempted to contact FCPS for more details, but did not receive a response.

The Maze gang is said to be behind the attack
As we said above, FCPS did not name the hackers but said that this particular group is behind dozens of attacks on other schools and businesses around the world.
However, the attack was likely carried out by the operators of the Maze ransomware, as 2% (about 100MB) of data said to have been stolen from Fairfax County Public Schools servers has already been leaked.
The data leaked by the Maze ransomware gang contains information about some of the students, as well as administrative documents. Also, something like an LSASS dump has been leaked that can be used to extract Windows credentials.
The Maze gang is the one that started stealing victims' data before encrypting systems, a tactic that has gradually been adopted by more and more groups. After stealing the data, the hackers threaten to leak it online if the victims do not pay the ransom.
Maze ransomware attacks were first detected in May 2019. Since then, hackers have greatly evolved their attacks through exploit kits, spam, and network breaches.
In November 2019, the first leak of stolen data occurred, belonging to Allied Universal. The company had been a victim of Maze ransomware but did not pay the ransom. So the hackers exposed the data. They then posted data from other victims on hacking forums, until they created their own leak site.
Maze ransomware has carried out many attacks on well-known and large companies, such as Chubb, Canon, Xerox, LG Electronics, Conduent, Cognizant, MaxLinear and others.
