Fall River Public Schools fell victim to a ransomware attack, disrupting critical systems and forcing data recovery teams to work urgently to restore operations. The attack targeted an older HR-related system (not the primary Aspen system managing students and staff), exposing potentially outdated but sensitive data, including names, addresses, Social Security numbers, attendance records, and employee conduct files. The FBI was involved in the investigation, though the ransom amount and origin remained unclear initial traces suggested routing through a southern U.S. state, possibly from a foreign source. The breach occurred during MCAS testing, adding operational strain. While the district’s insurance covered the incident, the exposure of personnel data even if dated poses risks of identity theft or fraud. Mayor Paul Coogan emphasized support for affected staff and families but acknowledged the uncertainty of the data’s misuse. The attack’s timing and scope disrupted administrative functions, though no immediate evidence suggested a broader compromise of student or real-time operational systems.
TPRM report: https://www.rankiteo.com/company/fall-river-public-schools
"id": "fal2732327090825",
"linkid": "fall-river-public-schools",
"type": "Ransomware",
"date": "4/2025",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 'students, staff, and families '
'(exact number unspecified)',
'industry': 'education (K-12)',
'location': 'Fall River, Massachusetts, USA',
'name': 'Fall River Public Schools',
'type': 'school district'}],
'customer_advisories': 'Mayor Coogan stated support for affected staff and '
'families; awaiting further communication',
'data_breach': {'data_exfiltration': "likely (data described as 'in the wrong "
"hands')",
'personally_identifiable_information': True,
'sensitivity_of_data': 'high (includes SSNs and personal '
'details)',
'type_of_data_compromised': ['personally identifiable '
'information (PII)',
'human resource data',
'student records (attendance, '
'conduct)']},
'description': 'Fall River School District suffered a ransomware attack, '
'disrupting systems and potentially compromising older human '
'resource data, including names, addresses, social security '
'numbers, attendance, and conduct records. The FBI is '
'investigating, and data recovery teams are working to restore '
'operations. The attack occurred during MCAS testing, adding '
'to operational challenges. The city’s insurance covers the '
'incident, and the source of the attack is suspected to be '
'international, routed through a southern U.S. state.',
'impact': {'brand_reputation_impact': 'Potential reputational harm due to '
'data breach and operational disruption',
'data_compromised': ['names',
'addresses',
'social security numbers',
'attendance records',
'conduct records'],
'downtime': True,
'identity_theft_risk': 'High (due to exposure of SSNs and personal '
'data)',
'operational_impact': 'Disruption during MCAS testing; systems '
"offline requiring 'all hands on deck' "
'recovery efforts',
'systems_affected': ['old website (likely legacy HR system)',
'Aspen system (not confirmed compromised)']},
'initial_access_broker': {'entry_point': 'old website (legacy system)',
'high_value_targets': 'HR data (names, SSNs, '
'addresses)'},
'investigation_status': 'ongoing (FBI involved, source tracing in progress)',
'ransomware': {'data_encryption': 'likely (systems taken offline, recovery '
'efforts underway)',
'data_exfiltration': 'likely (older HR data accessed)'},
'references': [{'source': 'NBC 10 News'}],
'response': {'communication_strategy': 'Public disclosure via NBC 10 '
'interview; planned discussion at '
'school committee meeting',
'incident_response_plan_activated': True,
'law_enforcement_notified': True,
'recovery_measures': 'Round-the-clock work to restore systems '
'(Aspen and legacy HR system)',
'remediation_measures': 'Ongoing system recovery efforts by '
'dedicated teams',
'third_party_assistance': ['FBI',
'data recovery teams',
'loss prevention teams',
'city insurance providers']},
'stakeholder_advisories': 'Planned discussion at school committee meeting '
'(Thursday night)',
'title': 'Ransomware Attack on Fall River School District',
'type': 'ransomware'}