Rutherford County Schools Targeted by Rhysida Ransomware Attack

Incident Date: Dec 11, 2024

Attack Overview
VICTIM
Rutherford County Schools
INDUSTRY
Education
LOCATION
USA
ATTACKER
Rhysida
FIRST REPORTED
December 11, 2024

Ransomware Attack on Rutherford County Schools: A Closer Look

Rutherford County Schools (RCS), a prominent public school district in North Carolina, recently fell victim to a ransomware attack orchestrated by the Rhysida group. This incident underscores the vulnerabilities educational institutions face in the digital age, particularly those with significant data and operational dependencies.

About Rutherford County Schools

RCS serves over 8,000 students across various educational levels, from pre-kindergarten to high school. The district is recognized for its commitment to educational excellence, having been designated as a national Apple Distinguished Program and operating a National Blue Ribbon School. Despite its accolades, the district's reliance on digital infrastructure for educational and administrative functions makes it a prime target for cyber threats.

Attack Overview

The Rhysida ransomware group claimed responsibility for the attack, which occurred on November 25, 2024, during the Thanksgiving holiday. The breach led to significant network disruptions affecting systems used by 52,000 students and 7,000 employees. Rhysida demanded a ransom of 20 Bitcoin, approximately $1,960,000, with a deadline set for December 18. The group has reportedly leaked sensitive documents, including passports, as evidence of their breach.

Rhysida Ransomware Group

Emerging in May 2023, Rhysida has quickly established itself as a formidable Ransomware-as-a-Service (RaaS) operator. The group is known for targeting sectors with high data sensitivity, such as education and healthcare. Rhysida employs sophisticated tactics, including phishing and VPN exploitation, to infiltrate networks. Their double extortion model, which involves encrypting data and threatening public exposure, places immense pressure on victims.

Victim Response

In response to the attack, RCS has restored most services through backup and recovery efforts and is working with law enforcement and cybersecurity experts to investigate the breach. The district has assured that no student data has been compromised, although investigations into employee data are ongoing.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.