Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

C2 provides technology services and consultation to businesses and individuals.

T (818) 584 6021
Email: [email protected]

C2 Technology Partners, Inc.
26500 Agoura Rd, Ste 102-576, Calabasas, CA 91302

Open in Google Maps
QUESTIONS? CALL: 818-584-6021
  • HOME
  • BLOG
  • SERVICES
    • Encryption
    • Backups
  • ABOUT
    • SMS Opt-In Form
    • Terms and Conditions
    • Privacy Policy
FREECONSULT
Tuesday, 29 September 2020 / Published in Woo on Tech

Hackers release student data in retaliation for ransom denial

There is an ongoing debate in the business world when it comes to deciding whether or not to pay a ransom demand when critical data systems are locked up in a successful ransomware attack. As a rule, technology and security professionals recommend against paying the ransom, but often times the business leaders will calculate the loss and potential risks against the ongoing and future harm the current lockout is causing, and decide to pay the money to get back to work quicker. This is a calculus that the attackers also weigh – how much is too much? What sort of threat does the ransomed data represent to the company?

What happens when they don’t pay?

Most of the time when the victim refuses to pay, the hackers move on to their next target, leaving their victim to pick up the pieces on their own. In the case of Clark County School District, critical school systems were compromised 3 days into the new school year. Despite threats by the attackers to leak the data they were holding hostage, CCSD choose to not pay the ransom, prompting the hackers to post some non-sensitive data as a warning that they meant business. When the CCSD continued to stand tough, the hackers apparently shrugged their shoulders and called the district’s bluff by posting the stolen data on both the regular and dark web, free and unprotected for anyone to download. The 25 gigabytes of data included employee social security numbers, addresses and retirement paperwork, as well as the PII of presumably the entire student body, including names, addresses, birth dates, grades and schools attended.

Previously, ransomware attacks seemed to be focused on businesses, allowing most folks to just shrug their shoulders (even if their own information was possibly compromised) as the impact was far removed from home. In this case, what if an organization over which you have very little influence made a decision that results in very real risk to your child’s future (and present!) livelihood? Clark County wasn’t the only school district to be targeted this year – Hartford, CT and Athens, TX school districts were targeted by similar ransomware attacks, resulting in closures and ransoms paid. As you might guess, schools are attractive targets – the stakes are high, and IT is typically not a high-priority budget item, making them easy targets. Even if the school systems had been backing up their systems (unlikely, see budget or lack thereof) it takes several days for systems to be restored even with a highly-trained and prepared IT team (unlikely), and meanwhile, the phone system is being lit like an angry Christmas tree by parents wondering what the heck is going on.

The reason ransomware attacks continue to be an extremely effective criminal activity is because how effective and profitable they can be. As is evidenced by their tactics and continued success, it’s very clear that ransomware campaigns are now an established weapon of organized crime. Unlike the stylized depictions of the “honorable mob” by Hollywood, today’s crime organizations seem to have no problem targeting our most vulnerable organizations, and aren’t squeamish about casualties along the way.

Image courtesy of Stuart Miles at FreeDigitalPhotos.net

  • Tweet

What you can read next

Email Credential Theft is Still Hot
Android Logo
Malware Apps for Android on the Rise
Java logo
Update Java but skip the shovelware

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Your Employees Are Already Using AI Wrong (They’re Just Too Scared to Tell You)

    Your staff is already using AI, whether you&#82...
  • The Accidental IT Person: What Happens When Your Office Manager Becomes Tech Support

    Nearly every professional services firm has one...
  • woman afraid of technology

    Why Your Team Fights New Technology (Fun Fact: It Has Nothing to Do With the Software)

    Employees resist new technology because it thre...
  • man working on his desk

    Why We Say Please and Thank You to AI

    A client of mine was using a Claude agent to he...
  • man working on open laptop

    Network Monitoring: Why Professional Services Firms Need 24/7 Oversight

    Your network does not take nights off. Neither ...

Archives

  • GET SOCIAL
Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

© 2016 All rights reserved.

TOP