DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Missouri school district’s employee data dumped by ransomware group

Posted on January 11, 2022 by Dissent

It’s a new year, but we are still seeing old problems with the education sector being compromised by ransomware attacks on the k-12 subsector.

Over the past weekend, threat actors known as Vice Society dumped data from Carthage R-9 district in Carthage, Missouri.

When contacted about the incident, a spokesperson for Vice Society informed DataBreaches.net that the attack occurred in the middle of December and the district had not made them a good offer to delete the files. Because they were busy in December, the spokesperson wrote, they did not spend a lot of time looking for good files from the district.

For its part, the district’s Superintendent, Dr. Mark Bayer, noted the incident in a Facebook post on December 14, and then acknowledged it in more detail on December 15, stating on its Facebook page:

We are experiencing a network outage affecting information technology systems and phone systems, and are working to restore access. On December 14, 2021, our IT staff noticed suspicious activity on the network and immediately implemented our incident response protocols, disconnected network access, and took systems offline to protect our network.

We are treating this matter with the highest priority. As part of our response process, we engaged many consultants, including independent forensic specialists, who are working to help us investigate the suspicious activity and resolve the outage. We are committed to completing a detailed analysis of our internal systems and will take all appropriate action in response to its findings.

I will update you as more information available.

Mark

DataBreaches.net has not found any update since that one.

Although it was easy to spot personnel/human resources files in the data dump,  a skim of the dump did not reveal any databases containing student or parent information. The biggest risk appeared to be to the more than 1,000 employees whose W-2 data, complete with social security numbers, has been dumped on the dark web.

Other personnel and human resources files such as payroll information, contracts, and other matters were also noted in the dump.

Inquiries sent to the district’s communication team and then to the superintendent and IT director over the past 36 hours have gone unanswered. If the district does provide a statement or if further inspection of the data dump reveals student data was exfiltrated and dumped, this post will be updated.

When the double extortion method first gained traction, threat actors like Maze often gave victims months before dumping any data (or even listing them on a leak site). Some groups — such as Pysa and Hive — still seem to give victims months before dumping data. Others seem to be using quicker timeframes recently. To the extent that some groups are giving victims a matter of weeks at best to respond, defenders or potential victims may need to look at their incident response plans and see if they have a plan that is triggered and implemented quickly enough.

Related posts:

  • k-12 school districts fall prey to Pysa ransomware
  • Four ransomware attacks on non-U.S. medical entities: Did anyone get notified?
  • “Without Undue Delay,” Part 2
  • Kept in the Dark — Meet the Hired Guns Who Make Sure School Cyberattacks Stay Hidden
Category: Education SectorMalwareU.S.

Post navigation

← Ph: Comelec investigating alleged data breach ahead of #Halalan2022
Connecticut company that hosts school websites recovering from ransomware attack →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Qantas customers involved in mammoth data breach
  • CMS Sending Letters to 103,000 Medicare beneficiaries whose info was involved in a Medicare.gov breach.
  • Esse Health provides update about April cyberattack and notifies 263,601 people
  • Terrible tales of opsec oversights: How cybercrooks get themselves caught
  • International Criminal Court hit with cyber attack during NATO summit
  • Pembroke Regional Hospital reported canceling appointments due to service delays from “an incident”
  • Iran-linked hackers threaten to release emails allegedly stolen from Trump associates
  • National Health Care Fraud Takedown Results in 324 Defendants Charged in Connection with Over $14.6 Billion in Alleged Fraud
  • Swiss Health Foundation Radix Hit by Cyberattack Affecting Federal Data
  • Russian hackers get 7 and 5 years in prison for large-scale cyber attacks with ransomware, over 60 million euros in bitcoins seized

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The Trump administration is building a national citizenship data system
  • Supreme Court Decision on Age Verification Tramples Free Speech and Undermines Privacy
  • New Jersey Issues Draft Privacy Regulations: The New
  • Hacker helped kill FBI sources, witnesses in El Chapo case, according to watchdog report
  • Germany Wants Apple, Google to Remove DeepSeek From Their App Stores
  • Supreme Court upholds Texas law requiring age verification on porn sites
  • Justices nix Medicaid ‘right’ to choose doctor, defunding Planned Parenthood in South Carolina

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.