UNITED STATES NEWS

White House holds first-ever summit on the ransomware crisis plaguing the nation’s public schools

Aug 8, 2023, 8:44 AM | Updated: 10:10 am

The White House on Tuesday held its first-ever cybersecurity “summit” on the ransomware attacks plaguing U.S. schools, in which criminal hackers have dumped online sensitive student data, including medical records, psychiatric evaluations and even sexual assault reports.

“If we want to safeguard our children’s futures we must protect their personal data,” first lady Jill Biden, who is a teacher, told the gathering. “Every student deserves the opportunity to see a school counselor when they’re struggling and not worry that these conversations will be shared with the world.”

At least 48 districts have been hit by ransomware attacks this year — already three more than in all of 2022, according to the cybersecurity firm Emsisoft. All but 10 had data stolen, the firm reported. Typically, Russian-speaking foreign-based gangs steal the data — sometimes including the Social Security numbers and financial data of district staff — before activating network-encrypting malware then threaten to dump it online unless paid in cryptocurrency.

“Last school year, schools in Arizona, California, Washington, Massachusetts, West Virginia, Minnesota, New Hampshire and Michigan were all victims of major cyber attacks,” the deputy national security advisor for cyber, Anne Neuberger, told the summit.

An October 2022 report from the Government Accountability Office, a federal watchdog agency, found that more than 1.2 million students were affected in 2020 alone — with lost learning ranging from three days to three weeks. Nearly one in three U.S. districts had been breached by the end of 2021, according to a survey by the Center for Internet Security, a federally funded nonprofit.

“Do not underestimate the ruthlessness of those who would do us harm,” said Homeland Security Secretary Alejandro Mayorkas during the summit, noting that even reports on suicide attempts have been dumped online by criminal extortionists and urging educators to avail themselves of federal resources already available.

Education tech experts praised the Biden administration for the consciousness-raising but lamented that limited federal funds currently exist for them to tackle a scourge that cash-strapped school districts have been ill-equipped to defend effectively.

Among measures announced at the summit: The Cybersecurity and Infrastructure Security Agency will step up tailored security assessments for the K-12 sector while technology providers, including Amazon Web Services, Google and Cloudflare, are offering grants and other support.

A pilot proposed by Federal Communications Commission Chair Jessica Rosenworcel — yet to be voted on by the agency — would make $200 million available over three years to strengthen cyber defense in schools and libraries.

“That’s a drop in the bucket,” said Keith Kroeger, CEO of the nonprofit Consortium for School Networking. School districts wrote the FCC last fall asking that it commit much more — Kroeger said some $1 billion could be made available annually from its E-Rate program.

He said he was nevertheless heartened that the White House, Departments of Education and Homeland Security and the FCC recognize that the ransomware attacks plaguing the nation’s 1,300 public school districts are “a five-alarm fire.”

The lasting legacy of school ransomware attacks is not in school closures, multimillion-dollar recovery costs, or even soaring cyber insurance premiums. It is the trauma for staff, students and parents from the online exposure of private records — which the AP detailed in a report published last month, focusing on data theft by far-flung criminals from two districts: Minneapolis and the Los Angeles Unified School District.

Superintendent Alberto Carvalho of the Los Angeles district, the nation’s second-largest, recounted for summit attendees lessons learned and best practices for mitigating the impact of extortionist ransomware attacks.

For starters, he said, “We don’t negotiate with terrorists. We did not pay the ransom.” Carvalho noted how the FBI told him that paying ransoms doesn’t guarantee the stolen data won’t eventually find its way onto dark web forums where hackers hawk it for use in ID theft, fraud and other crimes.

While other ransomware targets have fortified and segmented networks, encrypting data and mandating multi-factor authentication, school systems have reacted more slowly.

A big reason has been the unwillingness of school districts to find full-time cybersecurity staff. In its 2023 annual survey, the Consortium for School Networking found that just 16% of districts have full-time network security staff, down from 21% last year.

Cybersecurity spending by districts is also meager. Just 24% of districts spend more than one-tenth of their IT budget on cybersecurity defense, the survey found, while nearly half spent 2% or less.

United States News

Associated Press

Stock market today: World shares track Wall Street’s slump after Fed says rates may stay high in ’24

World shares have declined, echoing a slump on Wall Street after the Federal Reserve said it may not cut interest rates next year by as much as it earlier thought. Benchmarks fell by 1% or more in Paris, Tokyo, Sydney and Hong Kong. U.S. futures slipped and oil prices also were lower. On Wednesday, the […]

6 hours ago

FILE - Deja Taylor arrives at federal court, June 12, 2023, in Virginia Beach, Va. Taylor, the moth...

Associated Press

Mother of 6-year-old boy who shot his teacher in Virginia could be jailed for failing drug tests

NEWPORT NEWS, Va. (AP) — The mother of a 6-year-old who shot his teacher in Virginia could be jailed Thursday for failing drug tests while awaiting sentencing on federal weapons charges that she used marijuana while possessing a firearm. A bond revocation hearing is set in federal court in Newport News for Deja Taylor. Her […]

7 hours ago

FILE - Anthony Sanchez, right, is escorted into a Cleveland County courtroom for a preliminary hear...

Associated Press

Man set to be executed for 1996 slaying of University of Oklahoma dance student

McALESTER, Okla. (AP) — Oklahoma is set to execute an inmate Thursday morning for the 1996 slaying of a University of Oklahoma dance student, a case that went unsolved for years until DNA from the crime scene matched a man serving time for burglary. Anthony Sanchez, 44, is scheduled to receive a three-drug injection at […]

7 hours ago

A Brightline train approaches the Fort Lauderdale station on Friday, Sept. 8, 2023, in Fort Lauderd...

Associated Press

First private US passenger rail line in 100 years is about to link Miami and Orlando at high speed

MIAMI (AP) — The first big test of whether privately owned high-speed passenger train service can prosper in the United States will launch Friday when Florida’s Brightline begins running trains between Miami and Orlando, reaching speeds of 125 mph (200 kph). It’s a $5 billion bet Brightline’s owner, Fortress Investment Group, is making, believing that […]

7 hours ago

The entrance to the Las Vegas Review-Journal campus is shown in Las Vegas, Wednesday, Aug. 30, 2023...

Associated Press

Outdated headline sparks vicious online hate campaign directed at Las Vegas newspaper

NEW YORK (AP) — A Las Vegas newspaper is being viciously attacked online for its coverage of an alleged murder of a retired police chief, either because of a misunderstanding or a deliberate attempt to mislead. The “firehose of hatred” has led the Las Vegas Review-Journal to sift through email directed at one of its […]

8 hours ago

Disbarred attorney Alex Murdaugh arrives in court in Beaufort, S.C. Thursday, Sept. 14, 2023. Murda...

Associated Press

Alex Murdaugh plans to do something he hasn’t yet done in court — plead guilty

Convicted murderer Alex Murdaugh is expected to step before a judge Thursday and do something he hasn’t done in the two years since his life of privilege and power started to unravel: plead guilty to a crime. Murdaugh will admit in federal court that he committed 22 counts of financial fraud and money laundering, his […]

9 hours ago

Sponsored Articles

...

Mayo Clinic

Game on! Expert sports physicals focused on you

With tryouts quickly approaching, now is the time for parents to schedule physicals for their student-athlete. The Arizona Interscholastic Association requires that all student-athletes must have a physical exam completed before participating in team practices or competition.

...

DAY & NIGHT AIR CONDITIONING, HEATING AND PLUMBING

Here are the biggest tips to keep your AC bill low this summer

PHOENIX — In Arizona during the summer, having a working air conditioning unit is not just a pleasure, but a necessity. No one wants to walk from their sweltering car just to continue to be hot in their home. As the triple digits hit around the Valley and are here to stay, your AC bill […]

...

OCD & Anxiety Treatment Center

5 mental health myths you didn’t know were made up

Helping individuals understand mental health diagnoses like obsessive compulsive spectrum disorder or generalized anxiety disorder isn’t always an easy undertaking. After all, our society tends to spread misconceptions about mental health like wildfire. This is why being mindful about how we talk about mental health is so important. We can either perpetuate misinformation about already […]

White House holds first-ever summit on the ransomware crisis plaguing the nation’s public schools