Fauquier County Public Schools, a major school district in the US state of Virginia, said a ransomware attack aimed at its systems in September compromised the sensitive personal information of close to 14,000 students and staff.
Fauquier County Public Schools, a branch of the Fauquier County government in the US state of Virginia, runs 20 elementary, middle and high schools and has more than 11,200 students in its rolls.
In a statement shared with the media, a district spokesperson said that on September 12, the school district identified a cyber security incident affecting its systems and immediately launched an internal investigation, with assistance from third party cyber security experts, to understand the nature and scope of the incident.
“Upon learning of this, we took immediate action to begin an internal investigation and created an incident response team that includes some of the country’s leading cybersecurity experts. Fortunately, the impact was minimal and we have been fully operational.
“At this time we do not believe that any personal student or staff information has been compromised. We are grateful to our teachers and staff who have remained focused on the education of our students,” the spokesperson said.
In a recent
filing with the Office of the Maine Attorney General, Fauquier County Public Schools said that the district has so far found no evidence of any personal data being exfiltrated from the school’s internal database. However, there is a possibility that threat actors may have gained unauthorised access to a server that hosts a database containing the personal information of the District’s students and staff.
The compromised data includes students’ names, addresses, and medical information used to facilitate a safe and effective learning environment. For the District employees, the compromised data may include Social Security numbers, financial information, and driver’s license numbers.
The filing with the regulator also confirms that the ransomware attack has affected at least 13,919 students and school district employees. The District is providing two years of complimentary credit monitoring and identity theft protection services via Experian IdentityWorks to all individuals affected by the cyber attack.
The notorious LockBit ransomware gang recently claimed responsibility for the cyber attack on the Virginia school district and added the latter as a victim on its data leak site. The group demanded that the school district must pay a ransom by October 19, failing which the stolen data will be published.