Ransomware attack knocks out Scranton School District systems

Organization
Scranton School District
Exploit
Ransomware
Industry
Education

The Scranton School District in northeastern Pennsylvania confirmed in mid-March 2024 that a ransomware attack had disrupted its computer systems and services. Network problems surfaced on Thursday, March 14, and the district acknowledged the following day that ransomware was responsible.

The district, which serves roughly 9,000 to 10,000 students across 15 schools, opened two hours late on the day the attack surfaced and returned to a full schedule the next day. District technology remained off limits to staff and students in the immediate aftermath. Pupils completed assignments on paper rather than on their Chromebooks, some files were inaccessible, and the systems that stayed up ran slowly because of added security measures. The district website and Facebook page were unreachable, and telephone service, which ran through Zoom, went down. Employees were told to stay off school devices and to remove district applications from personal phones.

Acting Superintendent Patrick Laffey said the district was working with third-party forensic specialists to determine the source of the incident, confirm its impact on systems and restore full functionality. No ransomware group publicly claimed the attack, and the district did not say whether personal data had been taken.

Emsisoft threat analyst Brett Callow told The Record the incident was at least the 21st confirmed ransomware attack against a US K-12 school district in 2024.

Sources