Your district could be the next victim of a cyberattack initiated by an increasingly threatening criminal organization known as Vice Society. If that happens, is your district ready?
Vice Society most recently targeted the Los Angeles Unified School District, the second-largest in the country, with a ransomeware attack. The district had one month to decide whether it would pay the ransom or risk having their confidential data leaked. Ultimately, Superintendent Alberto Carvalho refused to capitulate to the group’s “insulting” demand, resulting in the release of their data. Carvalho explained that his reasoning for doing so was that paying a ransom doesn’t guarantee that all of the data won’t be compromised, and he is absolutely correct, writes Micah Ward for District Administration.
James Turgal, vice president of Optiv’s cyber risk Strategy and board relations, and former chief information officer for the FBI, outlines three scenarios schools should look out for as they address a ransomware attack.
Scenario 1
Assuming your school system has access to a crypto-currency account and can purchase a decryption key, keep in mind that a portion of the data will be unrecoverable. “There is no honor among thieves,” he says. A growing trend among most ransomware groups, he explains, is that they will always fall short of their demands in some regard.
Turgal says that on average, schools will lose around 26% of their data, even after they’ve purchased the decryption key. “Data loss occurs either because of how the ransomware was deployed or the network design,” he says.
Scenario 2
One of the more obvious situations a district might face is the classic scam, and schools should tread lightly. As Carvalho said regarding Vice Society, “We’re not about to enter negotiations with that type of entity.”
Turgal says that organizations will often demand a ransom from their target, receive the payment and never provide a decryption key because they never intended to.
Scenario 3
This is where it gets tricky. Your district’s decision to purchase a key might only stir up more trouble.
“The third scenario is when a victim pays the ransom and receives a decryption key, but the decryption key deploys new malware,” he explains.
Additionally, hackers sometimes use a tactic known as “piecemealing” to potentially rob schools of even more money. “Threat actors will piecemeal the stolen data and issue a ransom demand for the decryption key, and then issue subsequent ransom demands for not disclosing or releasing separate tranches of the data, which can end up in double and sometimes triple extortion,” he says.
Should schools pay off ransoms?
With these scenarios in mind, it’s important for districts to understand that while negotiation with criminal actors is seen as a business decision, it should not be based on the district’s financial resources.
“It should be based upon factors such as the extent of the damage to their network ecosystem, their forethought in having dedicated back-up and recovery systems that are not susceptible to becoming tainted and encrypted during the attack, and their ability to isolate the damage inflicted during the attack so that portions of their ecosystem are still available to operate their business,” Turgal says.
As discussed in the previous scenarios, he adds, there are little, if any, positive outcomes to paying a ransom. Paying will not stop them from releasing the stolen data they exfiltrated and/or selling it on the Dark Web to the highest bidder. And paying ransom increases vulnerability.
In the event of a cyberattack, always cleanse the system’s network ecosystems. Failure to do so, Turgal says, will likely lead to further attacks.
“I have worked hundreds of cases where victims of ransomware attacks pay the ransom, use the decryption key to recover most of their data, and then do nothing to cleanse their network ecosystems of the ransomware payload and code, only to be victimized by the same group six-18 months later,” he says.
Opting to pay ransom may reveal to other criminal groups that your district is willing to negotiate.
Secondly, he warns schools that paying a ransom to any prohibited organization on the Office of Foreign Assets Control list could lead to civil or criminal liability for the company and key executives. “The question of whether or not to pay the ransom must also be looked at through the lens of any regulatory body over the victim company and also the list of prohibited organizations,” he says.
In a previous District Administration article, Turgal addressed the power of information and why it’s important for smaller districts to band together. Schools should join The K12 Security Information eXchange.
Doing so, he says, allows law enforcement agencies that are also members of these groups to identify and respond to these incidents. First and foremost, however, schools should identify any flaws in their security network. Doing so will help districts protect their most valuable data.
“The first thing you have to do is understand what are the vulnerabilities and gaps on your networks in your ecosystem,” he said. “Have a cyber-risk assessment done. Very first thing. Because once you know, you now have a roadmap so you know what those vulnerabilities and gaps are. You can then prioritize, ‘O.K. what’s the most important data I’m trying to protect?’”
We’ll take a deeper dive into cybersecurity in a feature article in the winter issue of California School Business magazine. Don’t miss this extended coverage.