69传媒

Privacy & Security

COVID-19 and Cybersecurity: 鈥楥atastrophic Attack on Our Technology Systems鈥

By Mark Lieberman 鈥 December 01, 2020 7 min read
BRIC ARCHIVE
  • Save to favorites
  • Print
Email Copy URL

Two large school districts have been rattled in the last week by incidents related to internet security and privacy, as vulnerability to cyberattacks remains high during the current pandemic-era period of increased technology use.

In Baltimore County, Md., classes shut down the day before Thanksgiving due to what school officials a 鈥渃atastrophic attack on our technology systems.鈥 69传媒 remained closed Monday and Tuesday and are expected to reopen Wednesday. The district had been in fully remote learning mode that will last at least into January.

Meanwhile, in Chicago, parents and elementary school students were alarmed over this weekend when they received a series of unsavory, profanity-laced emails in their school inboxes during a 90-minute period in the morning. According to a , the initial message read, 鈥淚 do not know who I am. I do not know why I am here. All I know is that I must kill,鈥 and was followed by a series of replies that included question marks and vulgar language.

The incidents are different and unrelated. Baltimore County district officials have confirmed that the hack was a ransomware attack. District officials have been circumspect so far about the nature and extent of the breach, and whether sensitive data has been compromised or made public.

The Chicago incident, by contrast, 鈥渄id not pose an information security risk or permit access to anyone outside the CPS network,鈥 according to a statement from the district. A districtwide email group had inadvertently been set to allow anyone to respond to the entire group, the statement said. The district has not shared further details about the source of the messages.

These two incidents are the latest in a growing pile of reports from districts experiencing cybersecurity challenges this school year.

In Toledo, Ohio, district officials confirmed in early November that a ransomware attack had taken place in September after months of speculation among community members. That attack resulted in the dissemination of student and staff data, school officials said in a .

Some districts have yet to confirm apparent cyberattacks. The New Haven district in Connecticut was last month to determine the extent of an apparent attack on middle school students鈥 email accounts. The Norfolk district in Virginia as a preemptive measure after a district official noticed possible disturbances on the network.

The threats also extend to education companies. Stride, the for-profit education provider previously known as K12 Inc., that it is paying ransom to cybercriminals who recently invaded its network and is working with a third-party provider to determine the extent of the hack. A found that cyberattacks on education companies, while rare, can be serious because they can affect students across numerous districts.

69传媒 are among the institutions most likely to be targeted by hackers during this current period of heightened attention on cybersecurity threats, said Richard DeMillo, interim chair of the School of Cybersecurity and Privacy at the Georgia Institute of Technology. Public institutions that have a strong motivation to protect their data are always at a higher risk, and the pandemic has increased that risk because far more school activity is occurring using digital tools.

鈥淚t鈥檚 not that the threats are changing, it鈥檚 that the risks are growing,鈥 DeMillo said. 鈥淵ou should assume the more you鈥檙e doing online, the more the risks have gone up, the more serious the consequences would be if there were a serious breach.鈥

See Also

The Federal Bureau of Investigation alerted K-12 schools earlier this year that ransomware attacks on the rise, and has been assisting districts including Baltimore County when cybersecurity breaches crop up. The superintendent of the Hartford school district in Connecticut is among the scheduled speakers at a on the topic of cybersecurity threats facing state and local governments.

The Consortium for School Networking (CoSN), a membership organization that represents school IT leaders, has been advocating even prior to the pandemic for the Federal Communications Commission to allow funds from its E-Rate program for school connectivity to go towards strengthening cybersecurity protections. Districts have reported spending anywhere from $25,000 to $150,000 a year for basic firewall protections alone, according to a .

The recent spate of cybersecurity incidents affecting major districts only reinforces the urgency of those funds, said Keith Krueger, CEO of CoSN. He believes ongoing discussions about closing the digital divide need to more strongly touch on cybersecurity as a key component.

鈥淛ust getting devices and broadband connectivity, Wi-Fi, that alone is insufficient if the network isn鈥檛 usable, isn鈥檛 safe and secure,鈥 he said.

Understanding the Risks

Sean Gallagher, a senior threat researcher for the technology security firm Sophos, worked prior to this February as a journalist for the technology publication Ars Technica. In that capacity, he was researching Baltimore school networks last year in the aftermath of a ransomware attack on the Baltimore city school district, which is separate from the county district.

Using a search engine that detects cybersecurity vulnerabilities, he found that Baltimore County鈥檚 network protections hadn鈥檛 been updated to protect against one of the possible culprits of the Baltimore City attack.

Gallagher said in an interview he contacted the district at the time to flag those concerns, but never heard back. A district spokesperson didn鈥檛 respond to a request for comment.

A released just one day before Baltimore County schools closed last week reinforced Gallagher鈥檚 findings, identifying 鈥渟ignificant risks鈥 within the district鈥檚 network.

There鈥檚 not enough public information yet to determine whether the vulnerabilities identified in Gallagher鈥檚 2019 research or the 2020 state audit played a role in the current breach. But Gallagher said the series of events illustrates the importance of schools prioritizing cybersecurity efforts, and governments prioritizing funding for those efforts.

鈥淭hey really need to look at how they鈥檙e doing remote access, and take a really deep look at how their networks are connected to allow people to get in,鈥 he said.

In a survey conducted by the EdWeek Research Center in November, only 16 percent of teachers, principals, and district leaders said their school or district is engaged in full-time in-person learning. That means all the remaining districts have at least some remote learning currently taking place.

The more that schools have typically in-person activity happening on digital devices, the higher the risk becomes for a cybersecurity breach, according to DeMillo.

鈥淪taring at a computer screen in the privacy of your own home has now become a fairly public activity,鈥 DeMillo said. 鈥淭he level of hygiene it takes in order to keep that safe has to grow accordingly. That鈥檚 not a natural thing for a teacher to think about.鈥

How to Strengthen Protections

In the near term, experts said schools need to focus on raising awareness among employees of cybersecurity threats, and the role that their own activity could play in facilitating them.

Several Baltimore County teachers have shared on social media that their files have a Ryuk extension on them, according to a . The district has not confirmed that the breach was a Ryuk attack.

Regardless, the nature of Ryuk attacks is instructive, Gallagher said. They typically happen as a result of a single user clicking on an email message that contains an attachment or link. Clicking that link activates malware that can quickly spread to the whole system.

Most people are aware to some extent that cybersecurity is an issue, but getting them to follow through on that awareness with action can be much trickier, DeMillo said. Constantly reinforcing to administrators and teachers the importance of diligence is crucial, he said.

69传媒 also need to have policies and procedures in place for sharing the right amount of details of a hack that鈥檚 taken place.

鈥淓specially when you鈥檙e in the middle of a problem, you can鈥檛 always say everything publicly or you鈥檒l create a worse problem,鈥 Krueger said.

Fewer than 20 percent of school districts have a dedicated employee whose sole focus is cybersecurity, according to a 2020 survey of CoSN members. IT officials were stretched thin for tackling these issues even before COVID-19 and widespread digital learning.

鈥淭his isn鈥檛 something the average teacher or principal can handle. These are sophisticated cybercriminals targeting K-12,鈥 Krueger said. 鈥淚t鈥檚 just getting harder and harder.鈥

A version of this news article first appeared in the Digital Education blog.

Events

School & District Management Webinar Crafting Outcomes-Based Contracts That Work for Everyone
Discover the power of outcomes-based contracts and how they can drive student achievement.
This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of Education Week's editorial staff.
Sponsor
School & District Management Webinar
Harnessing AI to Address Chronic Absenteeism in 69传媒
Learn how AI can help your district improve student attendance and boost academic outcomes.
Content provided by 
School & District Management Webinar EdMarketer Quick Hit: What鈥檚 Trending among K-12 Leaders?
What issues are keeping K-12 leaders up at night? Join us for EdMarketer Quick Hit: What鈥檚 Trending among K-12 Leaders?

EdWeek Top School Jobs

Teacher Jobs
Search over ten thousand teaching jobs nationwide 鈥 elementary, middle, high school and more.
Principal Jobs
Find hundreds of jobs for principals, assistant principals, and other school leadership roles.
Administrator Jobs
Over a thousand district-level jobs: superintendents, directors, more.
Support Staff Jobs
Search thousands of jobs, from paraprofessionals to counselors and more.

Read Next

Privacy & Security Download A Tip Sheet to Help Teachers Prevent and Respond to Doxxing
Teachers can be a target for malicious actors. Use this tip sheet to prevent and respond to doxxing.
1 min read
Image of digital safety against doxxing and privacy invasion.
Laura Baker/Education Week via Canva
This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of Education Week's editorial staff.
Sponsor
Privacy & Security Quiz
Quiz Yourself: How Much Do You Know About Cybersecurity For 69传媒 And Districts?
Answer 6 questions about actionable cybersecurity solutions.
Content provided by 
Privacy & Security What 69传媒 Need to Know About These Federal Data-Privacy Bills
Congress is considering at least three data-privacy bills that could have big implications for schools.
5 min read
Photo illustration of a key on a digital background of zeros and ones.
E+
Privacy & Security Civil Rights Groups Seek Federal Funding Ban on AI-Powered Surveillance Tools
In a letter to the U.S. Department of Education, the coalition argued these tools could violate students' civil rights.
4 min read
Illustration of human silhouette and facial recognition.
DigitalVision Vectors / Getty