Menu
Browse

Cyber Incident Victim: Monroe Public Schools

Date:

Jun 2021

Location:

United States of America

Summary

Monroe Public Schools experienced a ransomware attack that encrypted systems and resulted in the exfiltration of a limited number of files, prompting immediate network containment and malware removal efforts followed by data restoration. The compromised information included social security numbers for some of the 1,201 notified individuals, though the district confirmed no student or parental data was involved and found no evidence of misuse; the specific malware type, ransom details, and whether affected parties were current or former employees remain undisclosed.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Monroe Public Schools in Michigan experienced a cybersecurity incident discovered on June 10, 2021, when unauthorized actors encrypted certain systems and files. The district immediately secured their network, removed the malware, and initiated efforts to restore data and functionality. A subsequent forensic investigation determined the attackers had accessed the network between June 9 and June 10, 2021, during which they both encrypted files and exfiltrated a limited number of files and folders. While the district's notification letter redacted specific data types involved, evidence indicated social security numbers were compromised for at least some affected individuals. The district explicitly stated no student or parental information was accessed or impacted by the breach.

Cyber Incident Image

On January 7, 2022, the district, through external counsel, began notifying 1,201 individuals whose data was potentially exposed during the incident. The notification did not specify whether affected parties were current employees, former employees, or a combination of both. Monroe Public Schools emphasized they found no evidence suggesting the exfiltrated data had been misused or would be misused in the future. The district declined to disclose the specific type of malware involved in the attack or whether a ransom demand accompanied the encryption event. Restoration efforts focused on recovering encrypted systems while maintaining operations following the containment measures implemented immediately after detection.

Sources
Sources available to members
1 source