Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Security Cyberattack topic

No spam. Unsubscribe anytime.

District 5 superintendent reports June cyber incident; investigation ongoing, no extortion payment made

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Superintendent Dr. Ross told the board the district detected a network intrusion June 3, restored operations June 26, and is working with law enforcement and a third-party forensic team; the district said it has no current evidence of data misuse and did not pay extortion demands.

Superintendent Dr. Ross told the School District 5 Board on July 21 that the district suffered a network intrusion detected June 3 and has been working with law enforcement and an external forensics vendor to determine the full scope.

The district’s technology team restored operations on June 26, Ross said, and administrators have been deploying advanced threat-detection software and reimaging devices. “We did not pay any extortion money,” Ross said during his report; the district has placed additional defensive software on its environment and is continuing the forensic review.

Why it matters: school districts store large amounts of student and employee data and depend on district networks for payroll, benefits and instruction. The speed of detection, the use of law enforcement and third-party forensic specialists, and a clear communications plan affect operational continuity and community trust.

What Ross reported - Detection and response: “On June 3, our staff detected that we were being impacted in our network. Operability has been impacted in our network environment. As soon as staff discovered this, they immediately called law enforcement and then started our protocols,” Ross said. (transcript) - Investigation and extortion attempt: Ross said initial findings show “malicious actors were inside of the district’s environment” and that “these threat actors attempted to extort us for money.” The district did not pay the extortion demand and retained a forensic team to investigate. - Operational restoration: Ross said the district was “fully restored to be operational on June 26.” The technology team has been reimaging devices and installing advanced threat software; Ross said “we have over 5,000 devices that our team is putting a new images on and this event advanced threat software on.” - Data exposure and next steps: Ross said the district does not store students’ Social Security numbers in its network, and staff are reviewing accessed files to determine whether personally identifiable information was exposed. “This will take some mining to find out,” he said, adding the forensic report had not been completed and that the district will notify affected people and work with counsel if the investigation identifies impacted individuals. Ross said the district will brief the board again when the investigation concludes.

Operational details and timeline - Detection: June 3 (staff first noticed network impact). - Restoration: June 26 (district reported restored operations). - Student devices: Ross said teachers and staff will see a sticker on reimaged laptops to indicate the device is cleared; Chromebooks are not subject to the same vulnerability, he said. - Return to school: Ross said the district planned to have systems ready when students return for the instructional year on August 7.

District posture and resource allocation Ross commended district teams for continuous work across technology, finance, human resources and instruction. He said the forensic review is ongoing and the district is applying additional defenses, but that “any protection that you can put in can be defeated if you know more about it,” adding that the district must balance transparency about defenses with operational security. The superintendent said the district will report findings to the board once the forensic investigation is complete.

What the board asked and next steps Board members asked clarifying questions about the data types stored by the district and how families would be notified if sensitive information is confirmed accessed. Ross reiterated there was no current evidence of misuse and emphasized the district’s ongoing forensic work and law-enforcement coordination. The district will return to the board with a completed report when the investigation concludes.