Edmonds School District, the public school district of Edmonds, Washington, in the US, said it suffered a significant cyber attack that compromised the sensitive personal information of close to 250,000 individuals.
Based in Lynnwood, Washington, Edmonds School District serves several cities such as Edmonds, Lynnwood, Mountlake Terrace, Woodway, and Brier. The school district has an annual budget of about $400 million and enrolls more than 20,000 students.
In January last year, the school district identified suspicious activities in its internal network and immediately launched an internal investigation, with assistance from third party cyber security experts, to understand the nature and scope of the incident.
“The investigation, which was conducted with the assistance of third-party forensic specialists, determined that an unauthorised actor had the ability to view and acquire certain information stored on the network between January 16, 2023, and January 31, 2023,” it said in a notice.
The school district said that the compromised data included the names and other personal identifiers, Social Security Numbers, financial account numbers, credit and debit card numbers in combination with their security codes, access codes, passwords and PIN for the accounts.
It added that while the investigation was concluded in September, it wasn’t able to locate several individuals who were impacted by the incident. The school district was finally able to notify all the affected individuals on 19th December with the assistance of third party vendors.
In its first filing with the state regulator in May, the school district
said that only 833 individuals were impacted by the data security incident. Later, in a separate filing, it
added another 91,325 individuals to the list of those impacted by the breach.
In another filing with the regulator on 5th January, Edmonds School District said that it
identified another 145,844 individuals whose data was compromised during the cyber security incident. THe school district’s latest disclosure takes the total number of affected victims to 238,000.
“Upon discovering the event, Edmonds moved quickly to investigate, respond to the incident, assess the security of its systems, and identify potentially affected individuals. Further, Edmonds notified federal law enforcement regarding the event,” the school district added.
Edmonds is offering a year of complimentary credit monitoring and identity protection services via IDX to all the individuals impacted by the incident.
On August 24, the infamous Akira ransomware group claimed responsibility for the cyber attack on Edmonds and listed the school district as a victim on its data leak site. According to a screenshot shared on X, the group claimed to be in possession of 10 gigabytes of organisations data which allegedly includes students’ personal documents, employee information, financial details, accounting data and more.
Last year, Middlesex County Public Schools in Virginia also suffered a significant ransomware attack that prompted a joint investigation by the FBI and the Department of Homeland Security.
In a statement shared with the media, Superintendent Dr. Tracy Seitz confirmed that the school system had fallen victim to a ransomware attack. Dr. Seitz assured the public that daily operations were minimally impacted, and the primary concern was to ascertain whether any personal information belonging to students or staff were compromised.
The Akira ransomware group claimed responsibility for the cyber attack on Middlesex County Public Schools, stating that it exfiltrated approximately 543 GB of data from the school’s network.