toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

290
active users

#edusec

0 posts0 participants0 posts today

Uvalde CISD in Texas will be closed for a few days while the district investigates a ransomware attack.

They have not disclosed whether there was any ransom note, and if so, who signed it.

KSAT reports, "The ransomware detected by the district is affecting several essential online systems, including phones, thermostats, camera monitoring and visitor management systems, among critical services, the district said." ksat.com/news/local/2025/09/13

It is not clear whether the attackers know Uvalde's tragic history of one of the worst school shootings in this country's history, where 19 children and 2 teachers were murdered and more than a dozen others were injured.

Do attackers really think that a district that has gone through so much is going to pay a ransom? Or did they just not know?

If they didn't know, I hope they find their souls and just give the district a decryptor and help.

If they knew and didn't/don't care, may they rot in Hell.

#EduSec #databreach #ransomware #cybersecurity #Uvalde

@douglevin @funnymonkey @brett @mkeierleber

KSAT San Antonio · Uvalde CISD to close most of next week due to ransomware issueBy Ivan Herrera

In other news, water remains wet. ico.org.uk/about-the-ico/media #edtech #edusec @PogoWasRight @brett @funnymonkey

EDIT: I honestly do not understand why students hacking their own schools seems to be such a big news story. It is hardly new and extremely commonplace - and has been for years. Significant school cyber incidents have been attributed to students. Is this not understood more widely? What is it about this notion that is new or novel to folks? I honestly don't understand.

ico.org.ukInsider threat of students leading to increasing number of cyber attacks in schoolsOver half of school insider cyber attacks caused by students 

The Muscogee County School District attack by Safepay in December 2024 has now been reported to the Maine Attorney General's Office as affecting 34,056 people.

It is hard to be sure from the notification letter because it uses variables, but the sample letter seems targeted to adults/employees rather than students or parents (unless there's a second letter that we are not seeing).

maine.gov/agviewer/content/ag/

I went to SafePay's site and it looks like they leaked the data on August 7. So far, there have been only a few downloads or attempted downloads of the compressed archive, but the download failed when I tried it so I'm not sure how big it is or what's in it at this point.

@douglevin @funnymonkey

www.maine.govOffice of the Maine AG: Consumer Protection: Privacy, Identity Theft and Data Security Breaches

@douglevin @funnymonkey

So let's attack school districts during summer vacation when staff may be away, right?

I've been swamped with other work and haven't had time to look into any of the following claimed or reported breaches, but here are some names of districts I've seen mentioned in the past few days:

Fort Smith Schools -- Qilin

Radford City Schools -- INC ransom
Franklin Pierce -- Medusa

Winner School District 59-2 -- Beast
Traverse City Area Public Schools -- Medusa
Ridgefield Schools -- ransomware attack reported in news

The St. Lawrence Lewis Board of Cooperative Educational Services ("BOCES") in New York has reported a breach that impacted 10,993 people. The types of information involved included: SSN, name, address, DOB, tax identification number, medical information, and financial account information.

The "cybersecurity incident" was discovered on August 12, 2024 and just reported this week to the Maine Attorney General's Office, although letters were sent out to those affected in June.

maine.gov/agviewer/content/ag/

#databreach #EduSec #cybersecurity

@douglevin @funnymonkey

www.maine.govOffice of the Maine AG: Consumer Protection: Privacy, Identity Theft and Data Security Breaches

The Clearbrook-Gonvick School District in Minnesota has disclosed a breach that occurred in October 2024. The types of information involved included names, Social Security numbers, driver's license or state ID numbers, individual taxpayer identification numbers, financial account information, and student identification numbers.

markets.financialcontent.com/s

#databreach #Edusec #cybersecurity

@douglevin @funnymonkey

markets.financialcontent.com · Notice of Data Privacy IncidentNotice of Data Privacy Incident

Breaches have consequences (sometimes):

"On Monday, the North Carolina State Board of Education approved a six-month, roughly $270,000 contract with PowerSchool for professional evaluations and onboarding services. The contract, NCDPI noted, isn’t related to the student information system, which was hacked in December. That system’s contract will expire at the end of June and won’t be renewed."

wect.com/2025/06/25/ncdpi-rene

#databreach #PowerSchool #EduSec #cybersecurity

@douglevin @funnymonkey @mkeierleber @brett

You may know this already, but in case you didn't: Threat actors have leaked some data from 2 more K-12 public school districts this week:

Some personal info on students at Coweta County School System was leaked by Nitrogen as proof of claims. I googled the parent information and found an exact match for name, address, and phone number.

Data from Kalamazoo Public School District was leaked by InterLock. InterLock claimed to have acquired 1,420 GB of data consisting of 724,477 Files and 82,820 Folders. It looks like they leaked it all but I didn't attempt to validate any data.

@douglevin @funnymonkey

Replied in thread

@FritzAdalis @scottwilson

That's not accurate. The Information's wording and organization may have confused people.

Para 5 in the Information is about Employee 1, a contractor who worked for PowerSchool. The Information does not say Employee 1 was a telco (Victim 1) employee or that their PS credentials were acquired as part of the telco breach. Para 5 is unrelated to Para 4.

The Employee 1 creds used to access PowerSchool were acquired at a separate time and unrelated to the telco breach. I confirmed that with a source with knowledge of the incident.

The Information: justice.gov/usao-ma/media/1400

Also of note: the Information makes no mention of the second round of extortion attempts, which may mean that DOJ had no evidence connecting Lane to the second set of extortion demands. The second round of extortion demands purported to be from "ShinyHunters," but whether they really were or not has yet to be publicly confirmed or refuted by law enforcement.

#databreach #EduSec #PowerSchool

@douglevin @funnymonkey @mkeierleber @campuscodi

@scottwilson I had the same reaction. I even emailed the Media contact for the Massachusetts USAO to ask why the information included enhanced sentences for use of "special skills" and use of "sophisticated means" under USSG § 3Bl.3 and USSG § 2B 1.1(b )(1 0)(C)), respectively.

What "special skills?"

What "sophisticated means?"

I suspect they won't really answer me, but... I had to ask.

#databreach #PowerSchool #EduSec #cybersecurity

UPDATING: The USAMA responded:

"The only information we can provide is that publicly available in the court filings - which are linked in the press release. Apart from that we have no comment. Thank you. "

Someone find me a good "shocked look" emoji, please.