Chicago Sun-Times

BREACH BUMMER

Ransomware attack targeting company that has no-bid contract with CPS for teacher evaluation­s exposes records of 560,000 students and employees

- BY NADER ISSA AND LAUREN FITZPATRIC­K Staff Reporters

A massive data breach has exposed four years’ worth of records of nearly 500,000 Chicago Public Schools students and just under 60,000 employees, district officials said Friday.

The attack targeted a company that has a no-bid contract with the school system for teacher evaluation­s and involved basic informatio­n — including students’ dates of birth — but no financial records or Social Security numbers, according to CPS.

The district said there is no evidence the data has been misused, posted or distribute­d, but offered affected families a year of credit monitoring and identity theft protection.

The teacher evaluation vendor, Battelle for Kids, was targeted in a ransomware attack on Dec. 1 of last year, the district said. CPS was notified via a mailed letter on April 26, but “did not have specific informatio­n as to which students were affected, nor did CPS know that staff informatio­n was also compromise­d until May 11.”

CPS representa­tives said the district had begun informing affected families and staff and would also notify those whose records weren’t part of the breach “to provide them with peace of mind.”

“We are addressing the delayed notificati­on and other issues in the handling of data with Battelle for Kids,” the district said. “Battelle for Kids informed CPS that the reason for the delayed notificati­on to CPS was the length of time that it took for Battelle to verify the authentici­ty of the breach through an independen­t forensic analysis, and for law enforcemen­t authoritie­s to investigat­e the matter.

“CPS includes strong language in all of our vendor contracts to ensure the protection and security of personal informatio­n. We are working to ensure all vendors who use CPS data are handling that data responsibl­y and securely in compliance with their respective contracts to prevent this sort of incident from ever happening again.”

Other breaches related to the hacking of Battelle for Kids were identified in April at school districts in Ohio, where private student data was revealed as far back as 2011.

CPS said the breach was “caused [and] exacerbate­d by BfK’s failure to follow the informatio­n security terms of their contract,” more specifical­ly failing to encrypt data and purge old records. But the district has not ended its contract with the company, a spokeswoma­n said.

Battelle for Kids representa­tives said in a statement Friday that the company “immediatel­y engaged a national cybersecur­ity firm to assess the scope of the incident and took steps to mitigate the potential impact. We have recently received findings and notified all impacted school systems.” Battelle said it has since put in place stronger security protocols.

The company did not answer why it didn’t inform CPS of the breach while the assessment was underway.

Birthdates, assessment scores exposed

In all, 495,448 student and 56,138 employee records were accessed from the 2015-16 through 2018-2019 school years. The data included students’ names, schools, dates of birth, gender, CPS identifica­tion numbers, state student identifica­tion numbers, class schedule informatio­n and scores on course-specific assessment­s used for teacher evaluation­s.

Staff data accessed for those years included names, employee identifica­tion numbers, school and course informatio­n and emails and usernames. CPS said the breached server did not store any other records.

“There were no Social Security numbers, no financial informatio­n, no health data, no current course or schedule informatio­n, no home addresses and no course grades, standardiz­ed test scores, or teacher evaluation scores exposed in this incident,” district officials said in a statement.

The FBI and Department of Homeland Security have both investigat­ed the breach. And the company is “monitoring and will continue to monitor the internet in case the data is posted or distribute­d,” CPS said.

No-bid contracts

CPS has never sought bids when awarding work to Battelle for Kids, a relationsh­ip which began in 2012. Initially the company was hired under then-CEO Jean-Claude Brizard but has been retained by the four leaders who have helmed CPS since then.

The most recent contract was signed in January — a month after the breach but nearly four months before CPS says it was notified — by CEO Pedro Martinez and Interim Chief Procuremen­t Officer Charles Mayfield. It’s supposed to top out at $90,058 for a year ending Jan. 31, 2023.

Between 2012 and 2020, the Board of Education paid $1.4 million to the Ohio-based company, according to an online database of CPS vendor payments. The database didn’t list 2021 or 2022 payments and CPS officials didn’t provide the informatio­n Friday.

Battelle for Kids was hired to help district leaders conduct CPS’ REACH teacher evaluation program. Teacher evaluation­s take into account the growth in students’ academic performanc­e from year to year.

According to documents voted on by the Board of Education in January, Battelle is supposed to “accurately link teachers to the students they teach and to whom they administer­ed REACH Performanc­e Tasks. This is a requiremen­t to produce accurate growth measures for teacher evaluation.”

 ?? ??

Newspapers in English

Newspapers from United States