vicesociety attacks Durham School

Incident Date:

January 12, 2022

World map

Overview

Title

vicesociety attacks Durham School

Victim

Durham School

Attacker

Vicesociety

Location

Quarryheads, United Kingdom

Durham, United Kingdom

First Reported

January 12, 2022

Durham School Ransomware Attack: A Cybersecurity Perspective

Victim Profile

Durham School, part of the Durham Cathedral Schools Foundation (DCSF), is committed to fostering moral integrity, ambition, responsibility, and kindness among its pupils. The institution is celebrated for its academic excellence and prowess in team sports, contributing significantly to the educational landscape.

Company Size and Industry Standing

The Durham District School Board oversees the operations of Durham School, catering to approximately 75,000 students and 14,000 staff in the Region of Durham, east of Toronto. This makes it one of the largest educational institutions in the area, with a substantial impact on the local community.

Vulnerabilities and Targeting

The cybersecurity defenses of educational institutions like Durham School can often be less fortified, making them attractive targets for ransomware groups. Vice-Society, the group behind this attack, is notorious for its focus on sectors such as education. The breach led to the encryption of critical data and has prompted an ongoing investigation into the extent of the data compromise.

Mitigation and Response

In response to the attack, Durham School has engaged in extensive efforts to restore its IT infrastructure and maintain the continuity of its educational programs. Collaborations with forensic cybersecurity experts and the National Crime Agency are underway to mitigate the attack's impact and bolster defenses against future threats.

The incident underscores the critical need for enhanced cybersecurity measures within the education sector. As reliance on digital technologies for teaching and administrative functions grows, so too does the imperative to safeguard digital assets against evolving cyber threats.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.