Engagements

Restored school operations through ransomware incident response

Computer security

The challenge

An educational institution experienced a ransomware attack that resulted in a partial network shutdown and the exfiltration of sensitive personally identifiable information (PII) and Family Educational Rights and Privacy Act (FERPA)-protected data. The incident occurred immediately before the start of the school year, threatening enrollment, class schedules, and tuition operations.

CRA approach

CRA’s Forensic Services team responded by deploying endpoint management and detection tools across 1,200 endpoints, providing immediate asset visibility and accelerating threat identification. Using proprietary scripts, we quickly detected and stopped malicious activity that had bypassed the client’s existing endpoint detection and response (EDR) solution.

Our investigation identified additional points of entry used by the threat actor, enabling the client to remediate critical vulnerabilities. We forensically documented accessed and exfiltrated data, providing the evidence necessary to support regulatory reporting under state and federal requirements.

A CRA team led the technical response from initial forensic investigation through remediation. Our team also negotiated directly with the threat actor to obtain a decryption key, a file tree of exfiltrated data, and proof-of-life files needed to assess the scope and impact of the incident.

The impact

CRA’s forensic intelligence provided the institution with the guidance required to mitigate risk, protect sensitive data, and minimize operational disruption. Our work enabled the institution to restore operations in time for the start of the school year and supplied the evidentiary foundation needed to meet FERPA and state data breach reporting obligations.

Key contacts