Springfield Public Schools in Massachusetts confirmed that cybercriminals stole data involving current and former staff and students during the September cyberattack. The district continues a phased recovery that includes reimaging thousands of laptops, according to a Sept. 30 update from the district.
The district said the compromised information appears to include medical information or notes, telephone information, student disciplinary information, demographic information, lesson plans, and test scores. Investigators are working to determine the scope of Social Security numbers in the stolen data; however, the district said it does not routinely store student Social Security numbers in its student database.
Springfield schools reopened Sept. 14 after a four-day closure due to the attack. On Sept. 15, the district first disclosed the data breach in a Sept. 15 Facebook post. In the post, the district said the FBI notified school officials that afternoon that district data appeared to include student and staff information. On Sept. 15, investigators informed the district that the criminal organization responsible for the attack released stolen information, according to the Sept. 30 update.
Springfield Public Schools secured two years of free identity protection services through IDX for district employees. It continues to explore protection measures for former employees and current and former students whose information may be compromised.
The attack disrupted systems needed for school operations, including access to student medical records. Essential operations have been restored, but technology access remains limited. Teachers are using available digital systems, printed materials, and other resources to maintain instruction, according to the district.
The district serves about 24,000 students.
“Springfield Public Schools will continue to prioritize security over speed,” the district said. “Systems and devices will return to service when technology professionals determine they can do so safely.”
The forensic investigation continues to examine how attackers entered the network, and the district is reviewing its technology infrastructure and cybersecurity practices and evaluating additional security tools, protocols, and training.