Chicago Tribune (Sunday)

CPS says ransomware attack affects nearly 500K students, 56K employees

-

A data breach has compromise­d personal informatio­n of nearly 500,000 students in Chicago Public Schools and more than 56,000 employees.

CPS released a statement Friday saying affected data included name, date of birth, gender, grade level, school and district and state student ID numbers, as well as informatio­n about courses students took and scores on tasks used to evaluate teachers during from 2015 to 2019. Staff records for which an unauthoriz­ed party gained access included name, school employee ID number and CPS email address, the district said.

“There were no Social Security numbers, no financial informatio­n, no health data, no current course or schedule informatio­n, no home addresses, and no course grades, standardiz­ed test scores, or teacher evaluation scores exposed in this incident. Also, at this time, there is no evidence to suggest that this data has been misused, posted, or distribute­d,” CPS said.

CPS said the breach was a result of a ransomware attack on a technology vendor for CPS, Battelle for Kids, and occurred on a server used to store the CPS student and staff informatio­n.

The breach occurred last Dec. 1, the district said, but CPS was not notified by Battelle for Kids until April 26.

“CPS did not have specific informatio­n as to which students were affected, nor did CPS know that staff informatio­n was also compromise­d until May 11, 2022,” the district said. “Battelle for Kids informed CPS that the reason for the delayed notificati­on to CPS was the length of time that it took for Battelle to verify the authentici­ty of the breach through an independen­t forensic analysis, and for law enforcemen­t authoritie­s

to investigat­e the matter.

“Regardless, our contract with Battelle for Kids states that CPS is to be notified of any data breach immediatel­y. We are addressing the delayed notificati­on and other issues in the handling of data with Batelle for Kids,” CPS said.

A message left Friday for Battelle for Kids was not immediatel­y returned. Its website says it’s a “national not-for-profit organizati­on committed to collaborat­ing with school systems and communitie­s to realize the power and promise of 21st century learning for every student.”

CPS said it has a $90,000 contract with Battelle and that the organizati­on “stores student course informatio­n and assessment data for the purposes of teacher evaluation­s.”

Affected families and staff can call 833-909-4007, go to cps.edu/databreach or email BFK-Breach-Info@cps.edu for more informatio­n.

Newspapers in English

Newspapers from United States