×

Union Community Schools respond after April data breach

During the spring semester, the Union Community School District was the victim of a ransomware cyber attack that briefly disabled the district’s computer network and may have put the personal information of thousands of Iowa residents at risk.

“On April 7, 2021, the district became aware of a network outage that caused a temporary disruption of our computer networks and IT systems,” Union Superintendent Travis Fleshner said. “At that time, the district had no facts indicating that any information was obtained. However, on April 21, 2021, the district learned that the unknown, unauthorized individual obtained some information from its systems during the incident.”

Following the details that emerged on April 21, the district engaged third-party forensic experts to conduct an investigation on the nature and scope of the incident and contacted the FBI to seek assistance and guidance.

Fleshner said results of the investigation indicated the unauthorized individual acquired certain information that was stored within the district’s network.

While the district was able to restore its networks and IT systems through a secure backup shortly after the April incident, exactly what information was illegally obtained during the attack remains unclear.

“Out of an abundance of caution, at that time, we began notifying individuals whose information was involved in providing additional guidance on how they can help to protect their information,” Fleshner said. “After that stage of our ongoing investigation, the district became aware of additional documents that an unauthorized individual may have accessed. Those documents are currently under review, and the district is committed to providing additional information to the community as quickly as possible.”

In a statement to the Telegraph on June 23, attorney Spencer Pollock, legal counsel for the district, provided an update on the investigation into the additional documents.

“On June 3, 2021, we learned that the unauthorized party obtained and released additional documents that contained personal information,” Pollock said. “We began a comprehensive review and examination of the documents and only recently discovered that certain personal information of additional individuals was included in these documents. There currently is no indication that this information has been misused.”

In a June 1 security breach notification sent to the Consumer Protection Division of the Iowa Attorney General’s Office, Pollock detailed the nature and scope of the incident and provided information of the district’s response efforts to those who may have been impacted.

As of June 23, an estimated 3,600 Iowa residents were involved in the security breach incident. The June 1 report classified the attack as a ransomware incident, but did not give detail as to demands made by the unauthorized individual.

The Cybersecurity and Infrastructure Security Agency defines ransomware as a form of malware designed to encrypt files on a device, rendering the files and connected systems unusable. Those that perpetrate the attack typically demand ransom in exchange for unlocking the affected files or threaten to leak the files if the ransom is not paid.

According to Fleshner, the district has not negotiated with the unknown unauthorized individual.

In a form letter sent to impacted residents in early June, the district said they had no evidence indicating personal information was obtained and or misused from the documents that were discovered in April.

However, in the June 3 investigation of the additional documents, Pollock said they did find evidence that personal identifying information was obtained.

Though it’s not clear exactly what sort of personal information was exposed, Pollock said the district would be issuing another security breach notification to the Iowa Attorney General’s Office, which will likely include additional details and response efforts the district will implement in the coming weeks.

In their initial letter sent to residents, the district strongly recommended those impacted to remain vigilant and to monitor and review all financial and account statements for signs of fraud.

As part of the district’s response to the incident, individuals potentially impacted were provided free access to credit monitoring services for 12 months, guidance on ways to protect against identity theft and fraud and resources for consumer reporting agencies and free credit report services.

The district is also working to implement any necessary additional safeguards, improve policies and procedures related to data protection, improve cybersecurity infrastructure and further train employees on best practices to minimize the likelihood of a similar incident occurring again.

According to Pollock, the district has cyberinsurance to protect against the financial impact of incidents like this, but total costs for legal fees, network administration and mitigation efforts in connection to the security breach are still being totaled.