澳门跑狗论坛

Privacy & Security

What Schools Can Learn From the Biggest Cyberattack Ever on a Single District

By Alyson Klein 鈥 March 30, 2022 2 min read
Gloved hand reaching into a laptop screen hacking someone's account.
  • Save to favorites
  • Print
Email Copy URL

Hackers successfully targeted a New York City public school district vendor, jeopardizing personal information for some 820,000 current and former students. It was the biggest cyberattack on a single school district in U.S. history, according to Doug Levin, the national director of the K12 Security Information Exchange.

Levin, who has been tracking said the January attack on the city school district is one of the clearest illustrations yet of how important it is that districts carefully vet the security practices of the vendors they work with.

The breach of Illuminate Education, whose software helped the nation鈥檚 largest school district track grades and attendance, means hackers now have access to personal information such as students鈥 names, birthdays, and special education and free-lunch statuses, .

The New York City education department has accused the vendor of misrepresenting its security measures.

鈥淲e are outraged that Illuminate represented to us and schools that legally required, industry standard critical safeguards were in place when they were not,鈥 David Banks, the district鈥檚 chancellor, told the Post.

The department did not immediately respond to questions from 澳门跑狗论坛 for more information.

See Also

Image shows a glowing futuristic background with lock on digital integrated circuit.
iStock/Getty Images Plus
Privacy & Security Explainer School Cyberattacks, Explained
Alyson Klein, February 11, 2022
12 min read

Illuminate is in the process of notifying individuals whose data may have been affected, the company said in a statement it provided to 澳门跑狗论坛. The company added that 鈥渢here is no evidence of any fraudulent or illegal activity related to this incident. The security of the data we have in our care is one of our highest priorities, and we have already taken important steps to help prevent this from happening again.鈥

That response leaves a lot of open questions, Levin said.

鈥淪ince they have not been forthcoming about what actually happened, it鈥檚 hard to know if they had a reasonable security program in place or not,鈥 Levin said. 鈥淛ust having an incident, in and of itself, should not necessarily mean that a company was negligent or acting in a reckless manner. Having said that, the lack of transparency here is concerning.鈥

It is possible that Illuminate misrepresented its cyber safeguards to the district, as the school system鈥檚 chancellor told the Post, Levin said. It鈥檚 also possible that the company was the victim of shrewd hackers, like those who have breached corporations that almost certainly spend more on cybersecurity than Illuminate, such as Microsoft, he added.

The breach comes as school districts across the country鈥攁nd the companies that serve them鈥攁re increasingly hit by sophisticated cybercriminals, many of whom operate overseas in countries that are tough for U.S. law enforcement to reach.

And it underscores the need for school districts to be vigilant not just about their own security measures, but those of their vendors, Levin said. Vendor hacks can cause all sorts of problems for schools, he explained, noting that .

鈥淪chool districts in general, and this is not just a critique of New York, have not been evaluating their vendors based on vendor security practice,鈥 said Levin. 鈥淓very type of vendor and supplier that a school district works with relies on technology, and if the school district relies on their services, they have an interest in ensuring that they have reasonable security practices in place.鈥

Events

Artificial Intelligence K-12 Essentials Forum Big AI Questions for Schools. How They Should Respond鈥
Join this free virtual event to unpack some of the big questions around the use of AI in K-12 education.
This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of 澳门跑狗论坛's editorial staff.
Sponsor
School & District Management Webinar
Harnessing AI to Address Chronic Absenteeism in Schools
Learn how AI can help your district improve student attendance and boost academic outcomes.
Content provided by 
This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of 澳门跑狗论坛's editorial staff.
Sponsor
Science Webinar
Spark Minds, Reignite Students & Teachers: STEM鈥檚 Role in Supporting Presence and Engagement
Is your district struggling with chronic absenteeism? Discover how STEM can reignite students' and teachers' passion for learning.
Content provided by 

EdWeek Top School Jobs

Teacher Jobs
Search over ten thousand teaching jobs nationwide 鈥 elementary, middle, high school and more.
Principal Jobs
Find hundreds of jobs for principals, assistant principals, and other school leadership roles.
Administrator Jobs
Over a thousand district-level jobs: superintendents, directors, more.
Support Staff Jobs
Search thousands of jobs, from paraprofessionals to counselors and more.

Read Next

Privacy & Security What Teachers Need to Know About Changes to Instagram Teen Accounts
The adjustments come as Meta faces multiple lawsuits from states and school districts.
4 min read
Close up photo of Black teen looking at Instagram photos on her cellphone.
Anastasia_Prish/Getty
Privacy & Security Download A Tip Sheet to Help Teachers Prevent and Respond to Doxxing
Teachers can be a target for malicious actors. Use this tip sheet to prevent and respond to doxxing.
1 min read
Image of digital safety against doxxing and privacy invasion.
Laura Baker/澳门跑狗论坛 via Canva
This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of 澳门跑狗论坛's editorial staff.
Sponsor
Privacy & Security Quiz
Quiz Yourself: How Much Do You Know About Cybersecurity For Schools And Districts?
Answer 6 questions about actionable cybersecurity solutions.
Content provided by 
Privacy & Security What Schools Need to Know About These Federal Data-Privacy Bills
Congress is considering at least three data-privacy bills that could have big implications for schools.
5 min read
Photo illustration of a key on a digital background of zeros and ones.
E+