FinalSite, a leading provider of school websites, has been hit by a ransomware attack that is disrupting access to websites for thousands of schools worldwide.

See also: AvosLocker ransomware hands over decryptor because it "hit" the police
FinalSite is a SaaS provider that offers website design, hosting, and content management solutions for K-12 school districts and universities. FinalSite claims to provide solutions for more than 8,000 schools and universities in 115 different countries.
On Tuesday, school districts that hosted their websites on FinalSite found that they were no longer accessible or displaying errors.
At the time, FinalSite did not disclose that they had been attacked, but simply said that they were experiencing errors and “performance issues” across various services, primarily affecting the Composer content management system.
A school IT administrator told BleepingComputer that FinalSite did not provide them with a timeframe for when services would be restored and was forced to email parents notifying them of the outage.
In addition to the website outages, a system administrator shared on Reddit that the attack prevented schools from sending out weather or COVID-19.
See also: The Lapsus$ ransomware gang “hit” the media company Impresa

Outages caused by a ransomware attack
After three days of outages, the company FinalSite confirmed today that a ransomware attack is causing the outages.
However, in a template created by FinalSite that schools can send to parents, there is no mention of the ransomware attack and simply that FinalSite is experiencing “an outage of certain computer systems on its network.”
It is not known which ransomware gang carried out the attack on FinalSite and whether any data was stolen as part of the attack.
As most ransomware targeting businesses steal data before encryption, we will likely learn that they gained access to the data in a future update.
See also: QNAP NAS devices targeted by eCh0raix ransomware
School districts and universities have become a popular target for ransomware operations lately.
Information source: bleepingcomputer.com
