Ransomware made its presence felt in the education sector and caused delays at some institutions at the start of the school year.

TechTarget Editorial’s ransomware database, which includes publicly confirmed or disclosed attacks in the United States, recorded 28 attacks last month, eight of which targeted the education sector. While some schools were able to address the attacks in time for the first day of school, others were unable to resolve the network issues in time.
The attacks targeted elementary and middle school schools and universities, consistent with the behavior of ransomware groups. The attackers continued to target the education sector in June, before the end of the school year for the summer. While data shows that the majority of schools do not succumb to ransom demands, attacks tend to increase as school activities begin in August and September.
On August 28, four days after the first day of school, the Chambersburg School District in Pennsylvania was forced to close due to computer problems. In a post on its Facebook page, the school district, which has more than 9,000 students, said it was working with experts to investigate the outage while schools remained closed. Students returned on August 31, two hours late and without internet access.
Following the outage, ABC27 reports that parents expressed concern about Chambersburg's lack of transparency about the incident. Last Thursday, school administrators issued a statement confirming that the network outage was due to a ransomware attack, although it's unclear whether the attackers stole any sensitive data.
On August 27, the University of Michigan announced that it had experienced an internet outage due to a “technology issue.” The next day, the university acknowledged how difficult the timing of the outage was, as the school year began on August 28. Although the college remained open and classes continued, financial aid resources were delayed and the campus internet remained down. The outage also affected a number of systems, including the M-Pathways student management system, the eResearch research platform, and the Donors and Alumni tool.
The school announced that internet access and Wi-Fi were restored on August 30 and attributed the outage to a “security issue,” although it did not confirm that a ransomware attack had occurred.

The Prince George's County School System in Maryland was the victim of a cyberattack on August 14, for which the Rhysida ransomware group later claimed responsibility. In an August 18 statement to ABC7, Andrew Zuckerman of PGCPS said the attack affected 4,500 users whose accounts were compromised. As of August 18, the investigation was ongoing and the school system was working to restore services. Zuckerman told ABC7 that they had initiated a district-wide password reset.
Last month, Bunker Hill in Massachusetts confirmed that it suffered a ransomware attack at the end of the spring 2023 semester in May that affected a “limited number” of the school’s systems. The Boston-based college posted a data breach notice on its website on Aug. 18. While the investigation with law enforcement is ongoing, information potentially affected includes student names, dates of birth, addresses, Social Security numbers and education records.
Information source: techtarget.com
