
Ever since the start of the COVID-19 pandemic, which saw many schools switching to temporary online-based remote learning, educational institutions and their providers worldwide have become a popular target for cybercriminals.
Roughly one month after leading private investment firm Veritas Capital acquired Finalsite, the education technology company has suffered a devastating ransomware attack, disrupting access and services of websites of about 5,000 educational institutions, including high schools and colleges, most of them in the US.
A cloud and software as a service (SaaS) provider that offers website design, hosting, and content management solutions for 8,000 schools and universities across 115 different countries, the Connecticut-based Finalsite discovered the ransomware on certain systems in its environment on Tuesday last week and immediately took its own network offline to prevent further attacks and rebuild everything in a clean environment.
“We proactively went offline immediately upon learning of what happened to protect and secure our data,” Finalsite spokeswoman Morgan Delack said. In doing so, we took approximately 5,000 school websites offline and rebuilt them in a new, safe environment. Because it was a complete reconstruction of data, it has taken some time to get up and going. At this time, the majority of our websites are back online in this new safe environment.”
The technology firm hired a third-party forensics team to investigate the attack and assist the recovery. The websites of most schools are back online by Sunday morning, but many institutions are still facing a variety of issues. For example, Tulsa Public Schools in Oklahoma said via Twitter that its website had functionality issues caused by the Finalsite cyber problems. Some sites still lack proper styling, admin log-in functionality, calendar events, or constituent directories.
The company urged their customers to limit “software usage to critical information updates for your front-end” until they have confirmed that all functionality is working fully. “Examples of usage to avoid include sending email/notifications, workflows, relying on the calendar and athletic alerts, uploading data, etc.,” the company said.
Finalsite claimed it had found no evidence that data had been stolen due to the ransomware attack, but the spokesperson declined to say whether Finalsite has the means, such as logs, to detect the exfiltration of data, citing an ongoing investigation.
It’s still unclear how the attackers gained access to Finalist’s computers and what type of ransomware was used in the attack. The company said that it continues to work with a forensic specialist to complete a thorough investigation. The investigation could take two weeks to complete. Notably, the attack surfaced roughly two months ahead of the Finalsite University 2022 user conference.
In addition to Finalsite, ransomware attacks have interrupted remotely learning for a number of schools in the US during the coronavirus pandemic. According to cybersecurity firm Emsisoft, ransomware has disrupted over a thousand K-12 schools in the United States in each of the last three years. Last year, 87 incidents disrupted learning at as many as 1,043 individual schools. In 2020, 84 incidents disrupted learning at 1,681 schools.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543