CSIDB logo
Incident

Buffalo Public Schools

Incident posture

Attack window
Mar 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-26 00:00

Linked entities

Victim
Buffalo Public Schools
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Buffalo Public Schools experienced a ransomware attack that disrupted operations, leading to the cancellation of remote classes. The district's IT department initiated immediate response efforts by engaging external experts experienced in handling similar cybersecurity incidents to mitigate the attack and restore services.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 12, 2021, Buffalo Public Schools canceled remote classes district-wide following a confirmed ransomware attack. Superintendent Kriner Cash publicly acknowledged the cybersecurity incident, which disrupted virtual learning operations during the pandemic. The district's IT department initiated emergency protocols immediately upon detecting the attack, entering what officials described as "problem resolution mode." Technical staff engaged external cybersecurity experts and professional colleagues with prior experience handling ransomware events to assist in containment and recovery efforts. No specific details regarding the ransomware variant, initial attack vector, or compromised systems were disclosed publicly. The incident occurred amidst heightened vulnerability for educational institutions transitioning to remote learning infrastructure, though the district did not confirm whether student or employee data was accessed or exfiltrated.

The ransomware attack caused immediate operational disruptions, forcing cancellation of all remote instructional activities scheduled for March 12. District leadership prioritized system isolation and forensic analysis to prevent further network compromise, though the full scope of impacted systems remained unspecified. Superintendent Cash's public statement confirmed the engagement of specialized cybersecurity professionals but provided no timeline for full restoration of services. The incident response focused on securing critical infrastructure while maintaining communication with relevant stakeholders. Educational continuity plans were affected during the outage, highlighting the attack's tangible impact on daily operations. Buffalo Public Schools maintained transparency about the event's occurrence while withholding technical specifics that could compromise ongoing investigations or remediation efforts.

Sources

Sources available to members: 1 source.

CSIDB