Security News > 2021 > March > And that's yet another UK education body under attack from ransomware: Servers, email, phones yanked offline
The Harris Federation, a not-for-profit charity responsible for running 50 primary and secondary academies in London and Essex, has become the latest UK education body to fall victim to ransomware.
In a message to pupils and parents, the group, which is led and run by teachers, admitted that criminals had meddled with its servers.
The group revealed the attack took place on 23 March, the very same day a warning was issued by the National Cyber Security Centre that the UK's education sector was being targeted by crooks.
Not only have servers been pulled offline, but both the telephone and email systems have been yanked, and each academy switchboard diverted to a mobile telephone.
"Cyber-criminals," the academy explained, "Have accessed our IT systems and encrypted, or hidden, their contents."
How the ransomware made its way into the Harris Federation's network is unclear, although following the trend, the group described the attack as "Highly sophisticated." The NCSC has highlighted phishing emails, shoddily configured remote access, and VPN vulnerabilities as common attack vectors and recommends a "Defence in depth" approach to both disrupt the attack vectors and enable recovery.
News URL
https://go.theregister.com/feed/www.theregister.com/2021/03/30/harris_federation_ransomware/
Related news
- CISA warns of Jenkins RCE bug exploited in ransomware attacks (source)
- CISA Warns of Critical Jenkins Vulnerability Exploited in Ransomware Attacks (source)
- Most Ransomware Attacks Occur When Security Staff Are Asleep, Study Finds (source)
- Most ransomware attacks occur between 1 a.m. and 5 a.m. (source)
- New Qilin Ransomware Attack Uses VPN Credentials, Steals Chrome Data (source)
- Lateral movement: Clearest sign of unfolding ransomware attack (source)
- BlackByte Ransomware Exploits VMware ESXi Flaw in Latest Attack Wave (source)
- U.S. Agencies Warn of Iranian Hacking Group's Ongoing Ransomware Attacks (source)
- Linux version of new Cicada ransomware targets VMware ESXi servers (source)
- Ransomware crisis deepens as attacks and payouts rise (source)