The school district of Lebanon was hit by a ransomware attack earlier this month, according to the departing inspector Joanne Roberts.
See also: MITRE: New list of the 25 most dangerous software bugs

After learning about the June 15 attack, the county hired “external cybersecurity experts” to help secure its systems and investigate the nature and scope of the attack, Roberts wrote in an email on Wednesday. For safety reasons, the county shut down systems such as payroll and PowerSchool, a database used to manage student information.
“Although the district maintains a robust data security program, which includes safeguards to mitigate the risk of cyberattacks, these attacks are becoming increasingly sophisticated and targeting organizations across multiple industries, including education,” Roberts wrote.
The investigation is ongoing, but so far, the district has found no evidence that any unauthorized acquisition or misuse of personal information, she said.
See also: Ransomware attack on Econsult: Employee information exposed
The region, which has about 1,600 students and 360 staff, also informed the personnel, the parents, the region's insurance provider, the US Department of Education and the local and federal law enforcement agencies about the attack. It will continue to provide updates as the investigation progresses, she said.
The Lebanese police officer Richard Norris, who oversees the department's cybercrime unit, said that the unit is cooperating with the region and its insurance authority to investigate the attack.
Norris said that there was an initial demand letter that did not ask for money and, as far as he knows, there was no second demand letter. The service is searching the “dark web” for evidence that any data collected from the attack are being used maliciously- if it finds them, it will inform the school district, he said.
Even though Norris stated that he is not aware of other ransomware attack victims in Lebanon, because the ministry learns about them only when they are reported, such attacks or attempts to access computer systems are common.
There are ways that both users and system administrators can protect themselves from such attacks. Users can prevent “bad actors” from gaining access to systems by avoiding opening file attachments and links from unknown sources. Administrators can help by granting users access only to the parts of a computer network that they need to access for their work. They can also implement email to look for common viruses and malware, Norris said.
If an employee happens to click on a malicious link or attachment, but does not have network access because they do not need it, the malware's the system is limited.

See also: Increase in the frequency of ransomware attacks without encryption in the last year
“I think education is the key when it comes to these things”, said Norris.
He urged users to be cautious about who they talk to online.
In the aftermath of the attack, Roberts said, the county is reviewing its procedures and processes to find ways to further strengthen its data security program.
Source of information: vnews.com
