{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-baltimore-county-schools-ransomware-started-with-a-contractor-opening-a"},"incident":{"slug":"2020-baltimore-county-schools-ransomware-started-with-a-contractor-opening-a","title":"Baltimore County schools ransomware started with a contractor opening a phishing email","date":"2020-11-24","date_precision":"day","year":2020,"victim_org":"Baltimore County Public Schools","sector":"Education","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Service Disruption","Data Breach"],"loss_usd":9700000,"loss_kind":"business_impact","loss_note":"About US$9.7 million in recovery and remediation costs according to the Maryland Office of the Inspector General for Education; no ransom was paid.","records_affected":null,"threat_actor":"Ryuk (reported)","summary":"Baltimore County Public Schools, one of the largest US school districts, was hit by ransomware on 24 November 2020, shutting down remote learning for about 115,000 students during the pandemic. A later investigative report by the Maryland Office of the Inspector General for Education found that a contractor had mistakenly opened a malicious email that initiated the attack, and that the district had not acted on prior security recommendations. Recovery costs reached roughly $9.7 million.","how_it_worked":"A contractor working with the district opened a malicious email attachment, which established the foothold that led to district-wide encryption on the eve of the Thanksgiving holiday, a timing choice that maximised the gap before anyone noticed. The Inspector General's report placed the weight of the finding not on the click but on what surrounded it: the district had received specific security recommendations from a prior state audit and had not implemented them, and had extended network access to a contractor without correspondingly hardened controls. Remote learning for 115,000 students halted, and rebuilding cost nearly ten million dollars.","lessons":"Contractor accounts need the same email defences, MFA and least privilege as employees, and audit findings left unimplemented become the incident's root cause.","confidence":"Confirmed","sources":[{"title":"Baltimore County schools ignored warnings before 2020 cyberattack, audit finds","url":"https://statescoop.com/baltimore-county-schools-ransomware-attack-2020-inspector-general/","publisher":"StateScoop"},{"title":"Report: Contractor 'mistakenly' opened email starting Baltimore County school cyberattack","url":"https://foxbaltimore.com/news/local/investigative-report-released-2-years-after-baltimore-county-schools-cyberattack","publisher":"Fox Baltimore (WBFF)"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-baltimore-county-schools-ransomware-started-with-a-contractor-opening-a"}}