CSIDB logo
Incident

Sir John Colfox Academy

Incident posture

Attack window
Mar 2019
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2025-11-04 00:00

Linked entities

Victim
Sir John Colfox Academy
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack targeted Sir John Colfox Academy after a staff member opened a malicious email impersonating a colleague from another school, encrypting files on the network. This resulted in the loss of Year 11 students' GCSE coursework for one subject and delayed Year 9 and 10 reports. The school confirmed no personal data was compromised, as such information was stored separately, and no ransom payment was made. Police and cyber crime specialists investigated, assessing no data exfiltration occurred. The institution liaised with exam boards regarding the lost coursework while working to restore systems. Experts highlighted broader vulnerabilities in educational institutions, noting under-reporting of such incidents and limited cybersecurity resources in schools.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 13, 2019, Sir John Colfox Academy in Bridport, Dorset, experienced a ransomware attack that encrypted files on its computer network, resulting in the loss of Year 11 students' GCSE coursework for one subject. The incident began when a staff member opened a malicious email disguised as correspondence from a colleague at another Dorset school. This email contained a virus that deployed ransomware, which proceeded to encrypt data stored on the school's system. The encrypted coursework could not be immediately recovered, directly impacting students preparing for exams. The attack also disrupted administrative functions, delaying Year 9 and Year 10 reports by at least one week. Head teacher David Herbert confirmed no personal data related to staff, students, or parents was compromised, as such information was not stored on the affected system.

The school initiated a multi-faceted response, engaging exam boards to address the lost coursework and hiring specialists to attempt data recovery. Dorset Police launched a full investigation, with its cyber crime unit providing direct support and confirming no ransom payment was made. Herbert publicly stated that police experts assessed it as "very unlikely" any school information had been exfiltrated. Concurrently, the incident highlighted broader vulnerabilities in the education sector, with technology specialist Mark Orchison noting 20% of schools reported cyber attacks—a figure he considered under-reported due to reputational concerns. Orchison's firm had demonstrated that school IT networks could be compromised in as little as four hours during security tests. The attack occurred amid a government warning about a "significant increase" in cyber incidents targeting academy trusts, underscoring systemic challenges like limited cybersecurity budgets and awareness in educational institutions.

Sources

Sources available to members: 1 source.

CSIDB