Ransomware Attack Hits Jordan Public Schools in Minnesota

Incident Date: Oct 29, 2024

Attack Overview
VICTIM
Jordan Public Schools
INDUSTRY
Education
LOCATION
USA
ATTACKER
Fog
FIRST REPORTED
October 29, 2024

Ransomware Attack on Jordan Public Schools by Fog Group

Jordan Public Schools, a medium-sized educational institution in Jordan, Minnesota, has recently been targeted by the notorious Fog ransomware group. This attack has compromised 11 GB of sensitive data, affecting the privacy and security of students, staff, and their families. The district, known for its commitment to academic excellence and community engagement, serves approximately 1,900 students across its elementary, middle, and high schools.

Overview of Jordan Public Schools

Jordan Public Schools is recognized for its diverse educational programs, including special education and gifted and talented education. The district's emphasis on extracurricular activities, such as athletics and student organizations, fosters a well-rounded educational experience. The district's Community Education and Recreation Center further highlights its dedication to community involvement. Despite its achievements, the district's reliance on technology, including providing Chromebooks to students, may have exposed vulnerabilities that threat actors like Fog could exploit.

Details of the Ransomware Attack

The Fog ransomware group has claimed responsibility for the attack, which involved the encryption of critical files and the exfiltration of sensitive data. The compromised information includes customer and employee contacts, student relatives' details, ID cards, and insurance documents. Such breaches can have severe implications for the affected individuals, potentially leading to identity theft and other security concerns. The attack underscores the growing threat of ransomware in the education sector, where sensitive data is often inadequately protected.

Fog Ransomware Group Profile

Fog ransomware, a variant of the STOP/DJVU family, has been active since November 2021. It is known for its rapid encryption capabilities and sophisticated attack mechanisms, including exploiting VPN vulnerabilities and using pass-the-hash techniques for privilege escalation. The group has recently shifted its focus to more lucrative targets, such as financial institutions, but continues to pose a significant threat to educational entities. The attack on Jordan Public Schools highlights the group's ability to infiltrate systems and exfiltrate data, leveraging double extortion tactics to pressure victims into paying ransoms.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.