Moody's: Cyberattacks Could Dent Higher Ed Credit Rating

Cyberattacks could affect the financial standing of higher education as a business segment, according to a recent briefing by Moody's Investors Services. The "sector comment" came out shortly after two big security events, both occurring on March 16, 2021. First, the Federal Bureau of Investigation's Cyber Division issued a "flash" warning about an increase in ransomware targeting education institutions. Then, Maricopa Community Colleges, one of the largest community college systems in the country, discovered it had been hit by "suspicious activity" and, in response, brought its network down, pushing off the start of classes after spring break by a week. The announcement came on March 19, three days after the discovery.

The FBI report specifically alerted readers about PYSA ransomware, also known as "Mespinoza," which is "capable of exfiltrating data and encrypting users' critical files and data stored on their systems." Current targets include colleges and universities, K-12 schools and seminaries.

According to the report, PYSA gains its unauthorized access through compromised Remote Desktop Protocol (RDP) credentials and/or phishing e-mails. Once the data is pulled out, the systems — files, databases, virtual machines, backups and applications — are made inaccessible to users through encryption and the attacker demands ransom. The ransom message contains information on how to contact the criminal via e-mail, displays frequently asked questions and offers to decrypt the affected files. If the ransom isn't paid, the hacker warns that the information will be uploaded and monetized on the darknet. The same FBI report discouraged victims from paying the ransom and urged them to report the incidents to their local FBI field office.

Maricopa Community Colleges, following its incident response protocol, took its systems offline, including its e-mail, user portal, learning management system, student information system, human resources management system and Google tools. The college system also brought in forensic and recovery specialists to help determine what had happened and to resolve the outage.

By March 29, classes had resumed, and by March 30 the operating systems had been restored. However, the forensic review was continuing, and the school couldn't report on whether data had been stolen.

Moody's warned that the rise in cyberattacks had come at an especially vulnerable time for higher ed. Not only have "some university finances ... become more fragile because of revenue declines and expense pressures related to the pandemic," but also "university networks have expanded more than ever as instruction is carried out largely online and most staff and faculty work remotely."

Unexpected school and course closures damage customer relations, the briefing noted. There's also the financial hit, which poses a "growing credit risk for debt issuers": The average data breach cost for an education victim is $3.9 million, according to a 2020 Ponemon Institute study.

The full briefing, "US: FBI warning for universities underscores vulnerability to cyberattacks," is available to Moody's subscribers.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • person signing a bill at a desk with a faint glow around the document. A tablet and laptop are subtly visible in the background, with soft colors and minimal digital elements

    California Governor Signs AI Content Safeguards into Law

    California Governor Gavin Newsom has officially signed off on a series of landmark artificial intelligence bills, signaling the state’s latest efforts to regulate the burgeoning technology, particularly in response to the misuse of sexually explicit deepfakes. The legislation is aimed at mitigating the risks posed by AI-generated content, as concerns grow over the technology's potential to manipulate images, videos, and voices in ways that could cause significant harm.

  • abstract image of fragmented, floating geometric shapes with holographic lock icons and encrypted code, set against a dark, glitchy background with intersecting circuits and swirling light trails

    Education Sector a Top Target for Mobile Malware Attacks

    Mobile and IoT/OT cyber threats continue to grow in number and complexity, becoming more targeted and sophisticated, according to a new report from Zscaler.

  • An abstract depiction of a virtual reality science class featuring two silhouetted figures wearing VR headsets

    University of Nevada Las Vegas to Build VR Learning Hub for STEM Courses

    A new immersive learning center at the University of Nevada, Las Vegas is tapping into the power of virtual reality to support STEM engagement and student success. The institution has partnered with Dreamscape Learn on the initiative, which will incorporate the company's interactive VR platform into introductory STEM courses.

  • Campus Technology Product Award

    Call for Entries: 2024 Campus Technology Product Awards

    The entry period for the 2024 Campus Technology Product Awards is now open.