And that's yet another UK education body under attack from ransomware: Servers, email, phones yanked offline
- Reference: 1617106329
- News link: https://www.theregister.co.uk/2021/03/30/harris_federation_ransomware/
- Source link:
The institution itself claimed it was "at least" the fourth multi-academy trust targeted just this month alone.
[1]
In a [2]message to pupils and parents, the group, which is led and run by teachers, admitted that criminals had meddled with its servers.
The group revealed the attack took place on 23 March, the very same day a [3]warning was issued by the National Cyber Security Centre (NCSC) that the UK's education sector was being targeted by crooks.
[4]
The impact of the attack was severe. Not only have servers been pulled offline, but both the telephone and email systems have been yanked, and each academy switchboard diverted to a mobile telephone. "Cyber-criminals," the academy explained, "have accessed our IT systems and encrypted, or hidden, their contents."
The break-in was discovered on 27 March, but as of yesterday the academy was still working to understand what had befallen it and what might or might not have happened. The National Crime Agency and NCSC are also involved, and the group is liaising with the Information Commissioner's Office.
And all those devices handed out to pupils? Now disabled "as a precaution."
The trust is just the latest educational establishment to discover its defences were not all they could be. The University of Northampton admitted on [5]17 March that its own network had been hit by [6]criminal activities , leaving phones and networks down and students struggling to submit assignments.
How the ransomware made its way into the Harris Federation's network is unclear, although following the trend, the group described the attack as "highly sophisticated." The NCSC has highlighted phishing emails, shoddily configured remote access, and VPN vulnerabilities as common attack vectors and recommends a "defence in depth" approach to both disrupt the attack vectors and enable recovery.
In a nutshell – patch, secure, educate and, for goodness sake, make sure those offline backups are both taken and actually work.
[7]
The Register has contacted the Harris Federation for more details and will update should a response be forthcoming. ®
Get our [8]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YGNLHiiefJWC0xlENfzYYwAAAIA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.harrisadvice.org.uk/?ts=1617090988230
[3] https://www.ncsc.gov.uk/news/alert-targeted-ransomware-attacks-on-uk-education-sector
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YGNLHiiefJWC0xlENfzYYwAAAIA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://twitter.com/UniNorthants/status/1372198570737209354
[6] https://www.bbc.co.uk/news/uk-england-northamptonshire-56500434
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YGNLHiiefJWC0xlENfzYYwAAAIA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://whitepapers.theregister.com/
it took them from Tuesday to Saturday to realise they didn't have phones or computers?
School networks do tend to be a bit more relaxed than a business or corporate network. This is usually because teachers refuse to have any security controls get in the way of teaching however they are absolutely the first to scream whenever anything goes wrong. I can only describe this as a an utter disconnect between cause and effect with teachers, i.e. if you have no security you will get hacked.
And computing teachers are the worst, I've had one demand that he was entitled to break the computer misuse act because, I quote, "I used to work for Microsoft so I know what I'm doing".
I would be good if NCSC could reinforce the idea that pupils losing all their data irrecoverably is also likely to "hinder teaching".
In terms of my IT Vs Teaching suffering I've spent 4yr as "the computer guy in one school" followed by 16yr dealing with them indirectly and 7yr married to a teacher.
My understanding is that at Universities academic staff are just as bad.
Universities and upward
Non teaching research institutions also suffer from this, as seen by the recent SSH hacks that affected HMC sites.
Basically, people don't like security getting in the way, and the more "important" someone is, the less they like to be restricted by security measures.
Worlds of difference...
SOME schools are more relaxed, some of us (that know what we're doing) keep it tightly locked down.
I work as a Network Manager for a set of Academies (Only started this year). I started off in one of our secondary schools long before Academies were a thing and worked my way up the ladder from there.
Our network settings make the security restrictions fairly tight - restrictions on what exes you can run, drives you can browse, very tight firewall rules, granular user share permissions, segmented permission based networking... You know, pretty much everything...
What I have seen however, is the abysmal state of the other schools. Most of them formerly had third party IT support (which I am spending the year transitioning away from) and most of the users have local admin rights and a wide open network. (There are a few schools that are somewhere between the two, but I would still class them as inadequate) - My "favourite" issue that I encountered is that one of the schools had a really obvious username with NO PASSWORD!
I think this may be a general problem with the way school IT is provided for - the usual "cost centre" mindset. For the large Secondary Schools, with their own /competent/ IT team, there shouldn't really be a problem, as long as managers/SLT/SMT are accepting of security risks and measures. (There are a LOT of incompetent IT Techs out there too!) For Primary Schools, and maybe the smaller Secondaries, it's a bit of a different story. Low budgets and high requirements tend to force them to outsource their IT requirements, quite often to a provider that will "maintain what you have" and everything else is an extra cost, that is basically unaffordable. Cheap switches with no network protection are added and very basic NAT firewalls with basic DNS filtering get used to "protect" the network.
The other problem, even for larger schools, is -as you say- "teachers refuse to have any security controls get in the way of teaching". Which is really a management issue. If you have a good set of Senior Leaders, they will listen to the security implications and usage restrictions of any security set-up and basically lay down the law. Where this goes wrong is when there's a particularly vocal teacher that needs things done his/her way and will get on everyone's case about it 24/7 until they get their own way. e.g. Particular software that wants to do something weird on the network (some remote computer control software with some unusual AD integration for example), adamant that they NEED a particular program to do their job, but it requires local admin rights to run. If the Senior Leaders back down to this kind of request, we require the request in writing an keep a log of our objections in case the worst happens.
Staff capability to spot any kind of scam, despite consistent reminders; guidance; and training, also seems to be a big issue. There was an incident not too long ago where someone managed to do it twice in the same week!
Well.... This was supposed to be a bit of an informative look into the massive differences in IT between schools, but turned into a bit of a rant as well - sorry about that!
TL;DR: Schools NEED at least 1 competent Network Manager, a leadership team that won't make "exceptions to the rules" if someone won't shut up, and if they're big enough - a few decent technicians.
Also: Outsourcing IT support when needing security expertise is a bad idea.
The institution itself claimed it was "at least" the fourth multi-academy trust targeted just this month alone.
So that's all right then, we're not the only ones.
And the others didn't serve as a warning?
Good to see that the sanctimonious are alive and well and still on El Reg. There is clearly an epidemic of ransomware out there. Is any organisation really safe? My guess is that the world is probably simply divided into 3.
1. Organisations where ransomware attacks have caused disruption already
2. Organisations where ransomware attacks will cause disruption
3. Organisations that don't own or use any computers
Harris Federation Report card
Security:
F. Could do much better.