Rhysida Ransomware Hits Fylde Coast Academy Trust Schools

Incident Date: Nov 05, 2024

Attack Overview
VICTIM
Fylde Coast Academy Trust
INDUSTRY
Education
LOCATION
United Kingdom
ATTACKER
Rhysida
FIRST REPORTED
November 5, 2024

Rhysida Ransomware Attack on Fylde Coast Academy Trust

In a significant cybersecurity incident, the Fylde Coast Academy Trust (FCAT), a prominent educational organization in the UK, has fallen victim to a ransomware attack orchestrated by the Rhysida group. This attack has severely disrupted the Trust's operations, affecting all ten schools under its management.

About Fylde Coast Academy Trust

Established in 2012, FCAT is a Multi-Academy Trust based in Blackpool, Lancashire, managing a diverse range of educational institutions, including primary, secondary, and all-through schools. With approximately 950 staff members, FCAT is dedicated to providing high-quality educational opportunities across the Fylde Coast and Lancashire. The Trust is known for its collaborative approach, fostering partnerships with local educational institutions to enhance teaching quality and leadership.

Attack Overview

The ransomware attack, which occurred in mid-September, has been claimed by the Rhysida group. The cybercriminals have reportedly exfiltrated sensitive data from FCAT and are demanding a ransom of £1.2 million. The attack has left the Trust's IT infrastructure in disarray, forcing schools to revert to manual processes due to limited access to essential technology. The hackers have also threatened to sell the stolen personal data on the dark web, escalating the potential impact of the breach.

Rhysida Ransomware Group

Rhysida emerged in May 2023 as a Ransomware-as-a-Service (RaaS) operator, quickly gaining notoriety for targeting critical sectors such as healthcare and education. The group employs a double extortion model, demanding ransoms for data decryption and to prevent public data exposure. Rhysida's tactics include exploiting phishing and VPN vulnerabilities, often using "living-off-the-land" techniques to blend into regular network activity and evade detection.

Potential Vulnerabilities

FCAT's reliance on IT infrastructure for educational services made it a prime target for Rhysida. The Trust's large-scale operations and the sensitivity of student data increased its vulnerability to ransomware attacks. The attack highlights the importance of effective cybersecurity measures, particularly in sectors where data sensitivity and operational continuity are critical.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.