DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Missouri school district’s employee data dumped by ransomware group

Posted on January 11, 2022 by Dissent

It’s a new year, but we are still seeing old problems with the education sector being compromised by ransomware attacks on the k-12 subsector.

Over the past weekend, threat actors known as Vice Society dumped data from Carthage R-9 district in Carthage, Missouri.

When contacted about the incident, a spokesperson for Vice Society informed DataBreaches.net that the attack occurred in the middle of December and the district had not made them a good offer to delete the files. Because they were busy in December, the spokesperson wrote, they did not spend a lot of time looking for good files from the district.

For its part, the district’s Superintendent, Dr. Mark Bayer, noted the incident in a Facebook post on December 14, and then acknowledged it in more detail on December 15, stating on its Facebook page:

We are experiencing a network outage affecting information technology systems and phone systems, and are working to restore access. On December 14, 2021, our IT staff noticed suspicious activity on the network and immediately implemented our incident response protocols, disconnected network access, and took systems offline to protect our network.

We are treating this matter with the highest priority. As part of our response process, we engaged many consultants, including independent forensic specialists, who are working to help us investigate the suspicious activity and resolve the outage. We are committed to completing a detailed analysis of our internal systems and will take all appropriate action in response to its findings.

I will update you as more information available.

Mark

DataBreaches.net has not found any update since that one.

Although it was easy to spot personnel/human resources files in the data dump,  a skim of the dump did not reveal any databases containing student or parent information. The biggest risk appeared to be to the more than 1,000 employees whose W-2 data, complete with social security numbers, has been dumped on the dark web.

Other personnel and human resources files such as payroll information, contracts, and other matters were also noted in the dump.

Inquiries sent to the district’s communication team and then to the superintendent and IT director over the past 36 hours have gone unanswered. If the district does provide a statement or if further inspection of the data dump reveals student data was exfiltrated and dumped, this post will be updated.

When the double extortion method first gained traction, threat actors like Maze often gave victims months before dumping any data (or even listing them on a leak site). Some groups — such as Pysa and Hive — still seem to give victims months before dumping data. Others seem to be using quicker timeframes recently. To the extent that some groups are giving victims a matter of weeks at best to respond, defenders or potential victims may need to look at their incident response plans and see if they have a plan that is triggered and implemented quickly enough.


Related:

  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • Confidence in ransomware recovery is high but actual success rates remain low
  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
  • TX: Kaufman County Faces Cybersecurity Attack: Courthouse Computer Operations Disrupted
  • Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
  • JFL Lost Up to $800,000 Weekly After Cyberattack, CEO Says No Patient or Staff Data Was Compromised
Category: Education SectorMalwareU.S.

Post navigation

← Ph: Comelec investigating alleged data breach ahead of #Halalan2022
Connecticut company that hosts school websites recovering from ransomware attack →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.