What happened
Baltimore County Public Schools, one of the largest US school districts, was hit by ransomware on 24 November 2020, shutting down remote learning for about 115,000 students during the pandemic. A later investigative report by the Maryland Office of the Inspector General for Education found that a contractor had mistakenly opened a malicious email that initiated the attack, and that the district had not acted on prior security recommendations. Recovery costs reached roughly $9.7 million.
How the deception worked
A contractor working with the district opened a malicious email attachment, which established the foothold that led to district-wide encryption on the eve of the Thanksgiving holiday, a timing choice that maximised the gap before anyone noticed. The Inspector General's report placed the weight of the finding not on the click but on what surrounded it: the district had received specific security recommendations from a prior state audit and had not implemented them, and had extended network access to a contractor without correspondingly hardened controls. Remote learning for 115,000 students halted, and rebuilding cost nearly ten million dollars.
The control that would have caught it· our reading, not a claim from the sources
Contractor accounts need the same email defences, MFA and least privilege as employees, and audit findings left unimplemented become the incident's root cause.
Sources (2)
- Baltimore County schools ignored warnings before 2020 cyberattack, audit findsStateScoop·statescoop.comOpen ↗
- Report: Contractor 'mistakenly' opened email starting Baltimore County school cyberattackFox Baltimore (WBFF)·foxbaltimore.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.