Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

Increased Cyber Threats Require New Jersey Schools to Take Action

Author: Scarinci Hollenbeck, LLC

Date: April 8, 2021

Key Contacts

Back

The Joint Cybersecurity Advisory warns that cyberattacks against K-12 educational institutions are on the rise

Increased Cyber Threats Require NJ Schools to Take Action

Cybercriminals are likely targeting schools, according to an Alert issued jointly by the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC). The Joint Cybersecurity Advisory warns that cyberattacks against K-12 educational institutions are on the rise, resulting in the disruption of remote learning, data theft, and ransomware attacks.

Uptick in Cyberattacks Against Educational Institutions

While learning has shifted online due to the COVID-19 pandemic, cybercriminals increasingly view schools as targets of opportunity. Schools are particularly vulnerable to cyberattacks since they were forced to quickly shift to remote learning environments in response to the pandemic; many staff members and students are new to online learning platforms; and many districts lack the resources to adequately safeguard their IT systems from mounting threats.

The FBI, CISA, and MS-ISAC continue to receive reports from K-12 educational institutions about the disruption to distance learning efforts at the hands of cyber actors. The cyberattacks have taken a variety of forms, including ransomware attacks, malware attacks, and distributed denial-of-service attacks.

Ransomware attacks have become particularly prevalent and disruptive in recent months. According to the FBI, in these attacks, malicious cyber actors target school computer systems, slowing access or even rendering the systems inaccessible for basic functions. Relying on tactics traditionally used against business targets, ransomware actors have also stolen—and threatened to leak—confidential student data to the public unless institutions pay a ransom.

Data collected by MS-ISAC shows that the percentage of reported ransomware incidents against K-12 schools increased at the beginning of the 2020 school year. In August and September, 57% of ransomware incidents reported to the MS-ISAC involved K-12 schools, compared to 28% of all reported ransomware incidents from January through July.

In the most recent string of ransomware attacks, cybercriminals used PYSA malware, also known as “Mespinoza”, to infiltrate schools in 12 states. According to an FBI Flash Alert, the cyber actors specifically targeted K-12 schools. The perpetrators used PYSA to exfiltrate data from victims prior to encrypting their victim’s systems to use as leverage in eliciting ransom payments.

Mitigation Strategies for New Jersey Schools

The FBI and CISA recommend that K-12 schools review or establish patching plans, security policies, user agreements, and business continuity plans to ensure they address current threats posed by cyber actors. While schools should thoroughly review the Alert in its entirety, below are several key steps to consider:

  • Focus on awareness and training. Provide users with training on information security principles and techniques as well as overall emerging cybersecurity risks and vulnerabilities (i.e., ransomware and phishing scams).
  • Implement multifactor authentication systems, where possible;
  • Regularly back up data, air gap, and password-protect backup copies offline. Ensure copies of critical data are not accessible for modification or deletion from the system where the data resides.
  • Implement network segmentation.
  • Implement a recovery plan to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, secure location (i.e., hard drive, storage device, the cloud).
  • Regularly, change passwords to network systems and accounts, and avoid reusing passwords for different accounts. Implement the shortest acceptable timeframe for password changes.
  • Install updates/patch operating systems, software, and firmware as soon as they are released.
  • Disable unused remote access/RDP ports and monitor remote access/RDP logs.
  • Audit user accounts with administrative privileges and configure access controls with least privilege in mind.
  • Install and regularly update anti-virus and anti-malware software on all hosts.
  • Only use secure networks and avoid using public Wi-Fi networks. Consider installing and using a VPN.
  • Consider adding an email banner to messages coming from outside your organizations.
  • Disable hyperlinks in received emails.

The Alert also offers best practices for safeguarding videoconferencing platforms such as Zoom and Google Meet. They include ensuring participants use the most updated version of remote access/meeting applications; requiring passwords for session access; establishing a vetting process to identify participants as they arrive, such as a waiting room; ensuring only the host controls screensharing privileges; and implementing a policy to prevent participants from entering rooms prior to host arrival and to prevent the host from exiting prior to the departure of all participants.

Schools should also recognize that their security is also influenced by the cyber controls implemented by their third-party service providers. Accordingly, when partnering with third-party and EdTech services to support distance learning, it is essential to consider the following:

  • The provider’s data maintenance and storage practices (e.g., use of company servers, cloud storage, or third-party services);
  • Types of student data the provider collects and tracks (e.g., PII, academic, disciplinary, medical, biometric, IP addresses);
  • Entities to whom the provider will grant access to the student data (e.g., vendors);
  • How the provider will use student data (e.g., will they sell it to—or share it with—third parties for service enhancement, new product development, studies, marketing/advertising?);
  • The provider’s de-identification practices for student data; and
  • The provider’s policies on data retention and deletion.
  • The service provider’s cybersecurity policies and response plan in the event of a breach and their remediation practices:
  • How did the service provider resolve past cyber incidents? How did their cybersecurity practices change after these incidents?
  • The provider’s data security practices for their products and services (e.g., data encryption in transit and at rest, security audits, security training of staff, audit logs);

Key Takeaway

Being proactive is essential to preventing a cyberattack. With the adoption of remote and hybrid learning, New Jersey schools face new threats and vulnerabilities that must be addressed with updated cyber policies, procedures, and training.

If you have questions, please contact us

For guidance, we encourage schools and school districts to reach out to a member of the Scarinci Hollenbeck Education Law Group or Cyber Security and Data Privacy Group at 201-896-4100.

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Scarinci Hollenbeck, LLC, LLC

Related Posts

See all
New York NDA Requirements for Businesses post image

New York NDA Requirements for Businesses

Non-disclosure agreements (NDAs) remain a critical tool for protecting sensitive business information. However, New York NDA requirements have evolved, and businesses must ensure these agreements are carefully drafted to remain enforceable. In a competitive market like New York City, NDAs are commonly used to protect proprietary information, client relationships, and strategic plans. At the same […]

Author: Dan Brecher

Link to post with title - "New York NDA Requirements for Businesses"
New Jersey Will Contest Grounds Explained post image

New Jersey Will Contest Grounds Explained

How Courts Evaluate Testamentary Capacity and Undue Influence Will contests in New Jersey are difficult to win, given the strong presumption that a properly executed will reflects the testator’s intent. However, challenges based on lack of testamentary capacity and undue influence remain common, particularly where there are concerns about mental capacity or the involvement of […]

Author: Marc J. Comer

Link to post with title - "New Jersey Will Contest Grounds Explained"
Legal Issues Before Bringing on Investors post image

Legal Issues Before Bringing on Investors

Bringing on outside investors can provide the capital and strategic support a business needs to grow. However, raising capital also introduces important legal, financial, and operational considerations. Before bringing on investors, businesses should address key legal issues to reduce risk, streamline investor due diligence, and position the company for long-term success. Early preparation signals that […]

Author: Dan Brecher

Link to post with title - "Legal Issues Before Bringing on Investors"
SECURE 2.0 RMD Planning Strategies post image

SECURE 2.0 RMD Planning Strategies

How the Updated Law Shapes Retirement and Estate Planning The SECURE 2.0 Act of 2022 materially reshapes the required minimum distribution (RMD) landscape, extending tax deferral opportunities while accelerating distribution requirements for many beneficiaries. For high-net-worth individuals and families, these changes are not merely technical. They require a reassessment of retirement income strategies, beneficiary planning, […]

Author: Marc J. Comer

Link to post with title - "SECURE 2.0 RMD Planning Strategies"
Buying Commercial Property in New Jersey: Legal Guide for Small Businesses post image

Buying Commercial Property in New Jersey: Legal Guide for Small Businesses

Small businesses considering buying commercial property in New Jersey must evaluate a range of legal, financial, and operational factors. While ownership can offer long-term value and control, it also introduces significant risks if not properly structured. This guide outlines key considerations to help New Jersey business owners make informed decisions, minimize legal exposure, and successfully […]

Author: Robert L. Baker, Jr.

Link to post with title - "Buying Commercial Property in New Jersey: Legal Guide for Small Businesses"
The SEC’s Latest Guidance on Applying Federal Securities Laws to Tokenized Securities post image

The SEC’s Latest Guidance on Applying Federal Securities Laws to Tokenized Securities

On January 28, 2026, staff of the U.S. Securities and Exchange Commission’s Divisions of Corporation Finance, Investment Management, and Trading and Markets issued a joint statement clarifying how existing federal securities laws apply to tokenized securities. The SEC’s “Statement on Tokenized Securities” does not establish new law, but it does provide greater clarity on the […]

Author: Dan Brecher

Link to post with title - "The SEC’s Latest Guidance on Applying Federal Securities Laws to Tokenized Securities"

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Sign up to get the latest from our attorneys!

Explore What Matters Most to You.

Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

Let`s get in touch!

* The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form. By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. You can reply STOP to opt-out of further messaging.

Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!