CSIDB logo
Incident

Baltimore City Public Schools

Incident posture

Attack window
Feb 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 12:16

Linked entities

Victim
Baltimore City Public Schools
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Feb 2025
Disclosed
Apr 2025
Resolved
Pending

Summary

On February 13, 2025, Baltimore City Public Schools experienced a cybersecurity incident that affected certain IT systems within their network, prompting immediate notification to law enforcement and engagement with external cybersecurity experts for investigation. The forensic review confirmed that criminal actors had compromised documents containing personal information belonging to some current and former employees, volunteers, and contractors, as well as files related to less than 1.5% of the student population. Affected individuals were notified by U.S. Mail and offered complimentary credit monitoring services alongside access to a dedicated call center for assistance. In response to the breach, the organization implemented additional security measures, including the deployment of endpoint detection and response software and a comprehensive password reset across all systems.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

3 techniques

Description

On February 13, 2025, Baltimore City Public Schools experienced a cybersecurity incident that affected certain IT systems within its network. Upon detection of the incident, the school system promptly notified law enforcement and began an initial investigation. Steps were taken to confirm the security of the systems, and external cybersecurity experts were engaged to assist with a thorough investigation guided by law enforcement. Through this investigative process, the school system confirmed that certain documents had been compromised by criminal actors.

The compromised documents contained personal information belonging to some current and former employees, volunteers, and contractors. In addition, files related to less than 1.5 percent of the student population were affected by the breach. The scope of the incident therefore extended beyond staff records to include a small fraction of student files, though the majority of the student population was not impacted.

In response to the confirmed compromise, Baltimore City Public Schools sent notification letters by U.S. Mail on April 22, 2025, to individuals who may have been impacted by the incident. The school system also committed to providing complimentary access to credit monitoring services to help mitigate any potential harm to affected individuals. More detailed information about these services was included in the notification letters received by those impacted. Additionally, a dedicated call center was established to answer questions and assist impacted individuals with enrolling in the offered mitigation services.

Following the incident, Baltimore City Public Schools implemented a series of additional cybersecurity enhancements to strengthen its defenses. These measures included the installation of endpoint detection and response software across the network and the resetting of all passwords. The school system indicated it would continue to assess existing procedures and the results of the forensic audit to identify further ways to defend against evolving threats. Law enforcement was notified early in the process and continued to provide guidance throughout the investigation. The school system expressed its commitment to safeguarding the privacy and security of all personal information stored on its servers and acknowledged the trust placed in it by students, families, and staff.

Sources

Sources available to members: 1 source.

CSIDB