New York Daily News

Schools fear ransomware

Evicted from eviction protest in Manhattan Suspect extortion attack on computer tracking grades

- BY MICHAEL ELSEN-ROONEY DAILY NEWS EDUCATION REPORTER

As the outage of the online grading and attendance system used by many New York City public schools drags into its seventh day, experts say they are worried the program was the target of a ransomware attack.

Skedula, the website many city teachers use to enter grades, daily attendance and store student and parent contact informatio­n, and PupilPath, its student-and-parent-facing counterpar­t, have been down since last Saturday with the exception of a brief restoratio­n of the mobile app Thursday night.

The California company that owns the platforms reported an “attempted security incident” led to the shutdown.

Experts who study cybersecur­ity and schools say the duration of the outage and the vague communicat­ion from the company could suggest a ransomware attack, where hackers infiltrate a computer system and demand payment to restore it or refrain from releasing sensitive data.

“Based on my experience tracking K12 cyber incidents since 2016, it seems a reasonable assumption that a security-related disruption of this length could be ransomware,” said Doug Levin, the national director of K12 Security Informatio­n Exchange, a group that tracks cyberattac­ks targeting schools and education platforms.

Kurtis Minder, the CEO of the cybersecur­ity firm Groupsense, said public speculatio­n that ransomware is behind the outage is “not completely uninformed.”

Illuminate Education, the company that owns Skedula and PupilPath, has given little public informatio­n about the situation. A status update page has given the same message for the past four days, promising the the company is working “diligently to restore service to affected applicatio­ns.”

A message on the Skedula home page says the company is working with “third-party forensic specialist­s to investigat­e the incident and confirm the effect to our systems.”

A company spokeswoma­n did not respond to questions Friday.

Levin says vague communicat­ion from companies or organizati­ons dealing with cyber or ransomware attacks is commonplac­e.

“In many cases, especially if lawyers, law enforcemen­t, and insurance companies are involved, organizati­ons will err on the side of disclosing as little as possible about what is actually happening,” Levin said. “In some cases, they may be gathering forensic evidence to charge someone with a crime; in other cases, they may be negotiatin­g with the ransomware actors to pay an extortion demand.”

“Some companies fear litigation and bad press so will say as absolutely little as they are allowed by law,” he added.

The ongoing outage raises several troubling questions for city schools and families.

First, many educators and families say it has severely hampered their ability to carry out basic classroom functions. Many teachers rely on the program to contact families, and vice versa, and the class-byclass attendance entry helps schools with COVID-19 contact tracing by providing a record of which kids shared a class with an infected classmate.

Department of Education officials noted final attendance and grades are entered in separate systems that were not affected.

Some anxious teachers are also worried that grades they entered in Skedula and didn’t back up elsewhere are gone for good.

The company has been in touch with some schools about “extracting” and sending data even while the website remains down, educators said. One city principal claims their school received a “data capture” with informatio­n including grades, but that it wasn’t presented in a user-friendly format.

Teachers reported that the Skedula mobile app was back up and running briefly

Thursday night — and appeared to still have all the data it did when the system shut down last Saturday — but went offline again Friday morning.

Levin said it’s a “good sign” the company was able to recover at least some of the data, but the fact the app went down again is “not a great sign.”

There is also the question of whether any “personal identifiab­le informatio­n” like student and parent addresses and phone numbers, which are stored in Skedula, were compromise­d. Company officials told The News on Tuesday there “is no confirmed evidence sensitive data was taken.”

DOE spokeswoma­n Sarah Casasnovas added, “So far there is no confirmati­on any of our schools’ informatio­n was accessed or taken.”

City public schools contract with Illuminate Education on an individual basis, but the company is an approved vendor of the city Education Department, which means it signed a privacy agreement with the agency and underwent a “a rigorous review process by” the DOE’s IT Department, agency officials said.

Schools have forked over nearly $17 million to the company since February 2019, payment records compiled by the city comptrolle­r detail, and about $6 million last fiscal year, according to the DOE.

 ?? ?? Protester is moved from a sit-in blocking street outside Gov. Hochul’s Midtown office following a march calling for an extension to the state eviction moratorium set to expire on Saturday.
Protester is moved from a sit-in blocking street outside Gov. Hochul’s Midtown office following a march calling for an extension to the state eviction moratorium set to expire on Saturday.

Newspapers in English

Newspapers from United States