D.C. Public Schools says student information from 55 schools, including families’ addresses, could have been exposed due to a data breach, according to school officials.
The school system sent a letter to families Wednesday saying that an unauthorized third party may have gotten access to information stored in a web-based application used for DCPS Summer Learning registration.
Stream NBC4 newscasts for free right here, right now.
“Upon learning of this incident, we immediately engaged the DC Office of the Chief Technology Officer (OCTO) to support a thorough investigation, removed student data from the affected application, and notified law enforcement,” said the letter from Yiesha Thompson, interim deputy chancellor of DCPS Finance and Operations.
Based on the investigation, the following information might have been exposed:
- Names
- Student identification numbers
- Dates of birth
- Schools and grade levels
- Parents’ or guardians’ names
- Home addresses
- Phone numbers
Grand Prix in DC: Info on road closures, Metro and possible airport delays
One killed, one critically injured in shooting in Shaw
“We are also evaluating additional safeguards for student information to reduce the risk of future incidents,” the letter read.
DCPS officials told News4 Thursday that the hack involved a website that was storing student data from 55 schools, mainly elementary schools, with after-school programs run by DCPS, as well as data from students in summer programs. You can see a PDF list of those schools here.
As of now, officials say they aren’t aware of any misuse of potentially stolen information.
Interim DCPS Chancellor Kim Jackson said officials are unsure who was behind the breach.
“We will know more with the investigation, once we get more information,” Jackson said.
DCPS told News4 they have now removed all the students’ personal information from that website as they decide whether they’ll continue to use the site in the future.
In the meantime, officials say that parents should be on the lookout for any unsolicited phone calls, emails, text messages or other communications requesting personal information.
The FBI is investigating the breach. In a statement, the agency said, “The FBI is aware of the incident and coordinating with partners to resolve the matter.”
Tony Monell, who works for the cybersecurity firm Black Kite, told News4 that people should use multifactor authentication whenever possible.
“Another thing you can do is you can create and use strong passwords. That’s something that a lot of folks just take for granted,” he said.
Monell said that although he is not part of the DCPS investigation, he’s noticed a hacker group on the dark web claiming responsibility for the breach. Monell said often hackers will either try to sell the information or demand a ransom.
“Ransomware groups oftentimes don’t target public schools because they’re easy. They target them because they’re essential,” Monell said.
DCPS says so far, there’s been no sign of the leaked information being used improperly. They are conducting a review of systems and processes associated with the data breach.
“We understand that data security incidents are concerning and sincerely regret that this occurred,” the DCPS letter said. “We remain focused on strengthening safeguards to protect student and family information.”
Families with questions may email datasecurity@k12.dc.gov.
