Highline Public Schools closed for three days after a cyberattack

Organization
Highline Public Schools
Exploit
Ransomware
Industry
Education

Highline Public Schools, a district headquartered in Burien, Washington and serving roughly 17,500 students across about 35 schools, announced on Sunday 8 September 2024 that it had detected unauthorised activity on its technology systems. The district cancelled classes the following day and kept schools closed for three days in total, on 9, 10 and 11 September, along with all activities, athletics and meetings.

The closures fell in the opening week of the school year and disrupted the first day of kindergarten. The district said it could not operate safely without the affected systems, which included attendance tracking, access to family contact information, and the software used to route school buses and confirm that students were dropped at the correct stops. Classroom phones worked only intermittently.

Highline said it had isolated critical systems and was working with third-party specialists alongside state and federal partners to restore and test them. Officials did not identify who was responsible or state a motive, and did not describe the incident as ransomware during the closures. No extortion group publicly claimed the attack in the days that followed.

Spokesperson Tove Tupper said that as of the weekend the district's specialists had not identified any theft of personal information belonging to staff or families. The investigation was still open when schools began reopening later that week. On 4 October 2024 the district confirmed that the unauthorised activity was a form of ransomware, said it had notified the FBI, and offered all Highline employees one year of free credit and identity monitoring. No group was ever publicly named.

Sources