Fall River Public Schools
Incident posture
Linked entities
- Victim
- Fall River Public Schools
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A public school district's internal network was breached by hackers, prompting the involvement of third-party cybersecurity experts and law enforcement to investigate and resolve the incident. The Chief Information Officer identified the cybersecurity event on a Monday, after which students and staff lost access to the district's wireless internet and Chromebooks, though school phone lines remained operational. As a direct consequence of the network disruption, scheduled MCAS testing was postponed, and automated attendance calls for absent students were temporarily suspended while attendance was still recorded manually across all locations. Officials confirmed there was no initial evidence that student or staff personal data had been accessed or misused, but they pledged to notify affected individuals immediately if this changed.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Monday, April 7, 2025, Fall River Public Schools discovered that its internal computer network had been breached by hackers, prompting an immediate response from district leadership, cybersecurity professionals, and law enforcement. Superintendent Tracy Curley notified parents of the incident in a written communication, stating that the Chief Information Officer, Scott Cabral, had become aware of the "cybersecurity incident" earlier that same day. At the time of the initial notification, Curley emphasized that there was no evidence indicating any personal data belonging to students or staff had been accessed or misused, while pledging that the district would promptly inform any affected individuals if that assessment changed. The district engaged "third-party cybersecurity experts and law enforcement" to assist with the investigation and remediation efforts, although Curley's letter did not specify the nature or method of the intrusion. According to internal sources within the school system, the disruption became apparent on Monday when many students found themselves unable to connect to the school's wireless network or use their Chromebooks.
The operational impact of the cyberattack rippled across the district, forcing significant adjustments to daily routines and scheduled academic activities. Curley communicated that most students and staff throughout the district would face a loss of internet access until the situation was resolved. MCAS testing, which was scheduled to begin the following day on Tuesday, was postponed, with Curley indicating that the testing schedule "will be altered" in response to the ongoing incident. Additionally, the district's automated attendance notification system was paused; instead of the typical phone calls alerting parents of absent students, attendance would now be taken manually at each school. Despite the widespread network and connectivity issues, Curley confirmed that all schools' phone lines remained operational, allowing continued voice communication between the schools and families.
The breach at Fall River Public Schools fits within a broader pattern of cyberattacks targeting educational institutions and public organizations in the surrounding region. While the specific type of attack against Fall River was not publicly identified, the article noted that ransomware incidents, where hackers break into networks and hold data hostage in exchange for cryptocurrency payments, can sometimes take weeks to fully resolve. Past incidents in nearby communities illustrate this recurring threat. In 2013, Swansea police paid $750, the equivalent of two Bitcoins at the time, to scammers who had encrypted files within their computer system. In 2019, the city of New Bedford endured a major ransomware attack in which criminals initially demanded $5.3 million in Bitcoin; the city countered with an offer of $400,000 from insurance proceeds, and after that offer was rejected, tech support successfully helped recover the data. Somerset Berkley Regional High School experienced a ransomware attack in 2020, while Newport schools were impacted by malware in 2019. Brockton police suffered a cyberattack in the summer of 2021 that knocked network systems offline, and in December 2022, Bristol Community College fell victim to a ransomware attack that disrupted operations across all campuses for weeks. The following month, Swansea Public Schools were forced to shut down for a day due to their own ransomware attack.
Sources
Sources available to members: 1 source.