Menu
Browse

Cyber Incident Victim: Manhasset Union Free School District

Date:

Sep 2021

Location:

United States of America

Summary

The Manhasset Union Free School District experienced a ransomware attack resulting in unauthorized access and public release of sensitive data on the dark web by the Vice Society threat group. Exfiltrated files included confidential student records such as Individualized Education Programs, disciplinary documents, medical information, and personnel investigations, some dating back over a decade. The district restored systems from backups without paying the ransom, leveraging network segmentation to facilitate recovery. Officials initiated a review of exposed data and committed to notifying affected individuals in compliance with legal requirements, offering complimentary credit monitoring for those whose Social Security or driver's license numbers were compromised. The attackers claimed the district's counteroffer was insufficient, leading to the data dump.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

In September 2021, the Manhasset Union Free School District on Long Island experienced a ransomware attack attributed to the Vice Society threat actor group. The district publicly confirmed the incident on October 7, 2021, after Vice Society published stolen data on their dark web leak site during the preceding weekend. Attackers encrypted the district's computer systems, though network segmentation enabled restoration from backups without ransom payment. The compromised data included extensive student and personnel records spanning over a decade, with particularly sensitive education files containing Individualized Education Programs (IEPs) for special needs students, disciplinary records, medical conditions, academic performance details, and letters of recommendation—all protected under FERPA and IDEA regulations. Personnel files contained employment investigations, salary information, and other confidential documents.

Cyber Incident Image

The district engaged cybersecurity experts and law enforcement following system encryption. Vice Society claimed the district made an insufficient ransom offer before data publication, though specific amounts were undisclosed. By October 18, the district issued a community letter confirming data exposure and outlining notification plans for affected individuals, with complimentary credit monitoring for those whose Social Security or driver's license numbers were compromised. The attackers characterized the breach execution as "not hard," while the district cited implementation of additional security measures to prevent recurrence. Legal obligations under FERPA required potential annotation of breached education records, including decade-old files, while New York state laws applied to exposed employee data. No evidence suggested district payment to attackers or exposure of comprehensive payroll databases.

Sources
Sources available to members
1 source