Analysis finds that nearly three dozen ransomware attacks have targeted US school districts educating 700,000+ students since the pandemic began in March
Tawnell D. Hobbs / Wall Street Journal : Tweets: @tawnell , @roberttgarrett , @csstewart , @zcobb , and @wsj Tweets: Tawnell Hobbs / @tawnell : Hey there! Thanks for sharing! One hacker, fresh from hacking a school district, told me that “high revenue and low cyber security is basically an open invitation.” https://twitter.com/... Bob Garrett / @roberttgarrett : Great look by our former colleague @Tawnell Hobbs at ransomware attacks on public school systems. Hackers threaten to release lists of kids' grades, foster kids' identities, etc. Riveting account of how Athens, Texas, school district escaped. https://www.wsj.com/... via @WSJ ChristopherSStewart / @csstewart : “The ransomware has gotten more heinous.” Hackers are going after schools more aggressively, posting sensitive student information. https://www.wsj.com/... Stephen Cobb / @zcobb : Foreign criminals steal millions of dollars from American schools every month while “tough on crime” President plays golf. https://www.wsj.com/... @wsj : Demands for payment in bitcoin. Threats to release student information. Inside new, aggressive cyberattacks on schools. https://www.wsj.com/...
Context & Ripple Effects
Schools were already a proven ransomware target before the pandemic: Armor counted over 500 US schools and colleges hit in 2019, including 100 across fifteen districts in a single two-week stretch. What changed in March 2020 is that remote learning pushed instruction, grading, and student records fully online, expanding the attack surface exactly when IT budgets were consumed by laptops and video conferencing.
The WSJ analysis of nearly three dozen attacks on districts educating 700,000-plus students is an early pandemic snapshot of what later tallies confirmed as a structural shift — Comparitech counted 77 attacks affecting 1,740 schools and roughly $6.6B in downtime for 2020, and by 2022 K12 SIX measured a 393% rise in K-12 attacks since 2016. The Athens, Texas district is the reporting's case study: hackers demanding bitcoin while threatening to publish grades and foster children's identities — extortion that monetizes sensitive data about minors, not just locked files.
First-order effects
- Affected districts like Athens ISD face a double bind: restore systems by paying bitcoin or refuse and risk publication of student grades, special-education records, and foster kids' identities — with no cyber staff to manage either path.
- Districts still running remote instruction lose their primary teaching channel when ransomware locks core systems, turning a data breach into immediate instructional outage for hundreds of thousands of students.
Second-order effects
- School boards and state education agencies are pushed toward cyber insurance, incident-response retainers, and security line items that compete directly with instructional spending in already tight budgets.
- The leak-threat playbook raises the stakes for every district that refuses to pay, since attackers' demonstrated willingness to expose minors' data pressures peers to treat payment as the cheaper option — reinforcing the attack pattern.
Third-order effects
- K-12 is consolidating as a standing target class rather than an opportunistic one — the trajectory from 2019's hundreds of incidents to the 2022 K12 SIX figures implies districts will need shared defense infrastructure (consortia, state-level SOC services) rather than district-by-district fixes.
- Sustained attacks on public institutions holding minors' data create the conditions for mandated baseline security standards and breach-disclosure rules for school systems, the way other critical sectors acquired them.
The trend: Ransomware is migrating toward soft-target public institutions like school districts, where remote learning expanded the attack surface and extortion increasingly monetizes threatened leaks of minors' data rather than encrypted files alone.