The Capital

Hacking puts Baltimore County schools in limbo

Experts say restoring network may take weeks; classes could be back in days

- By Liz Bowie and Alison Knezevich

Three days after a ransomware attack shut down Baltimore County’s school system, there is no indication the problem will be resolved quickly, and the timeline for resuming classes remains uncertain.

School officials issued a statement Friday saying the district continues to address the “catastroph­ic attack on our technology system” but gave no specifics on when online learning might be back up and running.

“Unfortunat­ely, we are limited in what we can say due to the ongoing federal, state and local investigat­ions,” the statement said, adding that updates will be provided at 4 p.m. each day.

The extensive ransomware attack closed school for the 115,000 students attending classes entirely online due to the coronaviru­s pandemic. Local officials have released little informatio­n about this week’s cyber attack, except to say that the county police department is working with the FBI and the state’s Emergency Management Agency. The county school system said the attack had affected many parts of its network.

Experts on ransomware attacks said while they do not have any specifics on the county’s situation, they believe it is likely the school district would be able to get online classes up and running in some form within aweek or two, and perhaps as soon as a few days. Other network operations could take much longer.

The school system announced Saturday that schools will be closed Monday and Tuesday.

There are many options available that don’t require teachers to plug into the county system, said Avi Rubin, technical director of the Johns Hopkins University Informatio­n Security Institute and a computer science professor.

When classes closed down inMarch for the coronaviru­s, he said, he was able to quickly put his class on a video conferenci­ng platform.

“In a pinch there are enough tools out there. There are ways to move to teaching even if it isn’t ideally the way we would teach,” Rubin said.

Fred Smalkin Jr., a technology attorney who worked in Baltimore’s law department during the 2019 ransomware attack oncity government, saidhis optimistic best guess is that students could be back in virtual school in about a week. His pessimisti­c guess is a fewweeks.

In the meantime, county officials need

to consider what to focus on first in terms of returning normal operations to the organizati­on. In some cases, the primary functions of paying people and getting communicat­ions running are as important as retrieving informatio­n.

Ransomware attacks typically block access to a computer system or files until money is paid.

“So really there are two things [officials] need to do in parallel. One is to figure out whathappen­ed and recover their systems,” Rubin said. “The second is to recover their online learning.”

Rubin and Smalkin said the pace of restoratio­n will largely depend on whether the school district has backed up its data regularly and whether the backups are infected with the ransomware.

One of the first signs that somethingw­as wrong with the network appeared Tuesday night when the school board meeting’s live stream abruptly cut out. Then teachers, who were entering first-quarter grades, weremet with blank screens orodd

messages that included the word Ryuk, which is a ransomware tool used by hackers.

Cyber attackers have have recently hit numerous school districts around the country.

In October, Fairfax County, Virginia, was a target. In that case, the attackers stole personal data and published it on the web, but did not interrupt the online classes, according to a report in The Washington Post.

Organizati­ons frequently bring in outside counsel as well as private cybersecur­ity firms to respond in a cyberattac­k crisis, Smalkin said.

The security experts can perform a kind of criminal profiling of the hackers, he explained. Strange as it may sound, they can help determine the trustworth­iness of the threat actors.

“You need to know these people and their reputation,” Smalkin said. “Have they followed through on theirword before?”

The outside experts can also help assess whether the hackers have ties to terror organizati­ons – because if the government pays the ransom, “you want to make sure you’re not funding terrorism inadverten­tly.”

In this type of crisis, an organizati­on’s first priority is figuring out its communicat­ion plan, Smalkin said. School system employees have been told not to use their email accounts, school laptops or accounts.

“If you don’t have communicat­ions, you can’t do anything,” he said.

The school system has a range of legal issues to consider, frommaking payroll and meeting obligation­s to contractor­s to notifying people if their data has been accessed.

School officials have not said whether students’ or teachers’ personal informatio­nwas stolen in the incident.

Cindy Sexton, president of the Teachers Associatio­n of Baltimore County, said teacherswe­re paid thisweek on schedule.

Teachers are concerned about connecting with their students and whether they will be able to retrieve lessons and grades.

“It is really stressful for everybody involved,” Sexton said.

State auditors found “significan­t risks” within the county schools’ computer network, according to a report released Tuesday.

The network was not adequately secured, and sensitive personal informatio­n was not properly safeguarde­d, among other issues, the Office of Legislativ­e Audits found.

Rubin, who reviewed the audit, said even if the attack had not happened, the vulnerabil­ities the audit described should have raised alarms.

“It is possible that a well-managed system could have still been hit, but when you look at a system that was poorly managed, it makes it more likely that this could have happened and been successful,” Rubin said. “They were not practicing good security.”

In particular, he said, systems have to be updated and “patched” or they are more vulnerable to attack.

While plans for classes in the county remain uncertain, school will be back to normal on Monday for Baltimore City students.

The day of the attack, surroundin­g school systems blocked emails from the county schools, and the city schools directed students using their personal computers to connect to online classes to leave school for the day. But Friday, city school officials said those students can rejoin classesMon­day.

Given what was happening in the county, said Andre Riley, a spokesman for the school system, “we just wanted to be cautious” and make sure that their network was secure by limited the access points.

 ?? ULYSSES MUÑOZ/THE BALTIMORE SUN ?? Mychael Dickerson, Baltimore County Schools Chief of Staff, listens during a news conference updating the public onWednesda­y’s ransomware attack.
ULYSSES MUÑOZ/THE BALTIMORE SUN Mychael Dickerson, Baltimore County Schools Chief of Staff, listens during a news conference updating the public onWednesda­y’s ransomware attack.

Newspapers in English

Newspapers from United States