Incident

Minneapolis Public Schools reports ransomware caused data breach


Learn More

Minneapolis Public Schools have started reporting to individuals whose personal information may have been compromised during a cyberattack that occurred in February. Notification letters are expected to reach affected households within the next two weeks.

The incident, initially referred to as an "encryption event," was first detected on February 18 when the school district's computer systems became inaccessible. Subsequent investigation revealed that a hacker had gained unauthorized access to the systems between February 6 and February 18.

In March, a ransomware group claimed responsibility for the attack and demanded a $1 million ransom while posting a 51-minute video that included screenshots showcasing a wide range of data, including

  • student names
  • addresses
  • potentially sensitive employee information.

The school district emphasized the importance of understanding the scope of the information accessed and collaborated with cybersecurity specialists on a comprehensive review of the affected computer systems to identify those affected.

No details are provided about the number of impacted individuals.

The process, which involved both automated and manual review, was time-intensive but crucial for ensuring accuracy and data integrity. The district is now offering free credit monitoring services to individuals impacted by the data breach and connecting others to support services for addressing mental or emotional responses related to the incident.

Additionally, the district is reviewing its policies and procedures, implementing enhanced security measures, and providing additional training to staff to mitigate the risk of future cybersecurity incidents.

Minneapolis Public Schools reports ransomware caused data breach
{ "@context": "https://schema.org", "@type": "FAQPage", "mainEntity": [ { "@type": "Question", "name": "What is the current status of the Minneapolis Public Schools data breach incident?", "acceptedAnswer": { "@type": "Answer", "text": "Minneapolis Public Schools have initiated the notification process for individuals whose personal information may have been exposed in a cyberattack that occurred in February. Notification letters are expected to be delivered to affected households within the next two weeks." } }, { "@type": "Question", "name": "When did the data breach incident in Minneapolis Public Schools take place?", "acceptedAnswer": { "@type": "Answer", "text": "The incident, initially referred to as an 'encryption event,' was first detected on February 18 when the school district's computer systems became inaccessible. Subsequent investigation revealed that a hacker had gained unauthorized access to the systems between February 6 and February 18." } }, { "@type": "Question", "name": "Who claimed responsibility for the cyberattack on Minneapolis Public Schools?", "acceptedAnswer": { "@type": "Answer", "text": "In March, a ransomware group claimed responsibility for the attack and demanded a $1 million ransom. They also posted a 51-minute video that included screenshots showcasing a wide range of data, including student names, addresses, and potentially sensitive employee information." } }, { "@type": "Question", "name": "What steps has the school district taken to address the data breach incident?", "acceptedAnswer": { "@type": "Answer", "text": "The school district emphasized the importance of understanding the scope of the information accessed and collaborated with cybersecurity specialists on a comprehensive review of the affected computer systems to identify those affected. They are now offering free credit monitoring services to individuals impacted by the data breach and providing support services for addressing mental or emotional responses related to the incident. Additionally, the district is reviewing its policies and procedures, implementing enhanced security measures, and providing additional training to staff to mitigate the risk of future cybersecurity incidents." } }, { "@type": "Question", "name": "Are there any details provided about the number of individuals impacted by the data breach?", "acceptedAnswer": { "@type": "Answer", "text": "No specific details are provided about the number of impacted individuals in the notification." } } ] }