Ransomware Attack on Hesperia Unified School District by LockBit 3.0

Incident Date:

May 16, 2024

World map

Overview

Title

Ransomware Attack on Hesperia Unified School District by LockBit 3.0

Victim

The Hesperia Unified School District

Attacker

Lockbit3

Location

Hesperia, USA

California, USA

First Reported

May 16, 2024

Ransomware Attack on Hesperia Unified School District by LockBit 3.0

Victim Overview

The Hesperia Unified School District, located in Hesperia, California, is a public school district serving students in the area, including elementary, middle, and high schools. The district is known for its diverse student population, with 17.6% of students identified as English Language Learners (ELLs).

Company Standout and Size

The Hesperia Unified School District stands out in the education sector for its diverse student population, reflecting the community it serves. The school district is a sizable educational institution with a workforce ranging between 1,001 and 5,000 employees. Their annual revenue stands at $306M reflecting the significant scale of their operations within the education sector.

Vulnerabilities

As an educational institution, the Hesperia Unified School District may be vulnerable to cyber attacks due to the sensitive nature of student data and the reliance on digital systems for educational purposes.

Attack Overview

The cybercrime group LockBit targeted the Hesperia Unified School District's website using ransomware to compromise their systems.

Ransomware Group: LockBit 3.0

LockBit 3.0 is a Ransomware-as-a-Service (RaaS) group that evolved from the original LockBit group. It is known for its advanced capabilities, including file encryption, desktop modifications, and obfuscation to evade detection.

Penetration Method

LockBit 3.0 likely penetrated the Hesperia Unified School District's systems through phishing emails, vulnerable software, or weak security measures, allowing them to encrypt files and demand ransom.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.