Ransomware Attack on Joliet Public Schools District 86 by LockBit Disrupts Operations

Incident Date:

July 19, 2024

World map

Overview

Title

Ransomware Attack on Joliet Public Schools District 86 by LockBit Disrupts Operations

Victim

Joliet Public Schools District 86

Attacker

Lockbit3

Location

Joliet, USA

Illinois, USA

First Reported

July 19, 2024

Ransomware Attack on Joliet Public Schools District 86 by LockBit

Overview of Joliet Public Schools District 86

Joliet Public Schools District 86, established in 1857, serves a diverse student population from pre-kindergarten through eighth grade in Joliet, Illinois. Covering an area of 26.4 square miles, the district educates approximately 9,872 students with a student-teacher ratio of about 14:1. The district is committed to providing a high-quality, inclusive, and equitable education, aiming to empower students to grow into responsible citizens and lifelong learners.

Details of the Ransomware Attack

On July 19, 2024, Joliet Public Schools District 86 fell victim to a ransomware attack orchestrated by the LockBit group. The attack has disrupted the district's operations, potentially compromising sensitive information and impacting the educational services provided to the community. The extent of the data leak remains unknown at this time.

About LockBit

LockBit, also known as LockBit Black, is a highly sophisticated ransomware-as-a-service (RaaS) group active since September 2019. It has become the most active ransomware group, responsible for over one-third of all ransomware attacks in the latter half of 2022 and the first quarter of 2023. LockBit employs "double extortion" tactics, exfiltrating sensitive data and threatening to release it publicly if the ransom is not paid. The ransomware uses a combination of RSA-2048 and AES-256 encryption algorithms to encrypt victims' files.

Potential Vulnerabilities and Penetration Methods

LockBit is designed to exploit vulnerabilities in Remote Desktop Protocol (RDP) services and unsecured network shares to spread quickly across a network. It performs a check to avoid executing on computer systems with installed languages common to the Commonwealth of Independent States (CIS) region. Indicators of Compromise (IOCs) for LockBit include the creation of a mutual exclusion object (Mutex) when executed, the use of a unique icon, and changes to the victim's computer wallpaper. The ransomware group distinguishes itself by its modular design, which encrypts its payload until execution to hinder malware analysis and detection.

Impact on Joliet Public Schools District 86

The ransomware attack on Joliet Public Schools District 86 has significant implications for the district's operations and the community it serves. The disruption caused by the attack could affect the district's ability to provide educational services and compromise sensitive information. Given the district's commitment to educational excellence and community engagement, the attack underscores the importance of robust cybersecurity measures to protect against such threats.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.