Hackers are demanding hundreds of thousands of dollars in ransom from the Slate Valley Unified School District after hacking a district server last month and compromising teachers’ personal information, according to Superintendent Brooke Olsen-Farrell.
The incident continues to wreak havoc on the district after hackers breached the district’s internet system in early September and obtained teachers’ records, she said Friday.
Many questions remain unanswered according to district leadership: Who is behind the attack? Where are they based? Why was the district targeted?
“It’s absolutely, you know, a challenge to navigate,” she said.
The district first learned it had been attacked by a ransomware group on Sept. 3 when teachers came in to school and couldn’t log in to Microsoft Windows. The district was without internet and internal platforms, like the grading system Powerschool, for a week before it was able to restore connection with the help of its cyber security contractors, Olsen-Farrell said.
The district is seeking information from the FBI, which is investigating the incident, and from cyber security firms, who the district is paying hundreds of thousands of dollars to pinpoint which teachers had their information compromised, Olsen-Farrell said.
The district has been able to restore its internet and the school board denied making any ransom payments earlier this week.
Meanwhile, the purported hackers, who call themselves Kairos ransomware group, wrote in an email addressed to members of the media that they possess personal information from Slate Valley staff.
“The personal info of more than 1,500 employees — including SSNs and home addresses and other highly confidential information is about to be leaked,” they wrote.
Olsen-Farrell said the email was “an extortion attempt.”
Cyber security websites recognize Kairos as a group that has gained traction since emerging in 2024. The group has been paid ransom by a county in Ohio in the past, according to The Hacker News, a cyber security publication.
Similar emails written under the name “Kairos Support Group” have been sent out to staff and community members in the district, said Lindsey Hedges, policy and communications specialist for the Vermont Agency of Education, in an email.
“We are urging members of the Slate Valley community who receive suspicious communications not to respond or engage with the sender, click links, open attachments, call phone numbers provided in the message, or provide personal or financial information,” Hedges said.
“Suspicious emails should be preserved and forwarded to the district,” she wrote.
Sarah Ruane, a spokesperson for the FBI’s office in Albany, confirmed in an email that the bureau is investigating and assisting with the incident. The bureau itself was recently hacked by a group eager to solicit the press in an incident that compromised the data of thousands of its employees.
“As this is an ongoing investigation, DOJ policy prevents me from providing any additional information,” Ruane wrote.
Olsen-Farrell said the FBI cautioned them against paying the ransom, advising that paying the hackers incentivizes them and can lead to future attempts. She declined to disclose the dollar amount the hackers demanded while the investigation is ongoing but said they were asking for hundreds of thousands of dollars.
“This is, you know, kind of new territory for me. I think these types of things are increasing with AI,” she said.
The district reached out to the education agency to alert them to the issue, she said, but the agency wasn’t equipped to respond to the issue.
Hedges said the education agency is working to support Slate Valley and ensure that families and staff in the district have clear information about how to recognize suspicious outreach.
So far, the district believes that the personal information of current and former teachers has been compromised, according to Olsen-Farrell, so the district has notified staff about the breach.
“We’re working with a third-party outside consultant to assess every person’s name that was impacted and to make the proper individual notification. So that takes quite a bit of time,” she said.
The district expects to be reimbursed by its cybersecurity insurer for the costs of hiring outside cybersecurity firms and legal experts, Olsen-Farrell said.
“Certainly, I hope that this doesn’t happen to others and other school districts,” she said.
Click Here For The Original Source.
