Moody's: Cyberattacks Could Dent Higher Ed Credit Rating

Cyberattacks could affect the financial standing of higher education as a business segment, according to a recent briefing by Moody's Investors Services. The "sector comment" came out shortly after two big security events, both occurring on March 16, 2021. First, the Federal Bureau of Investigation's Cyber Division issued a "flash" warning about an increase in ransomware targeting education institutions. Then, Maricopa Community Colleges, one of the largest community college systems in the country, discovered it had been hit by "suspicious activity" and, in response, brought its network down, pushing off the start of classes after spring break by a week. The announcement came on March 19, three days after the discovery.

The FBI report specifically alerted readers about PYSA ransomware, also known as "Mespinoza," which is "capable of exfiltrating data and encrypting users' critical files and data stored on their systems." Current targets include colleges and universities, K-12 schools and seminaries.

According to the report, PYSA gains its unauthorized access through compromised Remote Desktop Protocol (RDP) credentials and/or phishing e-mails. Once the data is pulled out, the systems — files, databases, virtual machines, backups and applications — are made inaccessible to users through encryption and the attacker demands ransom. The ransom message contains information on how to contact the criminal via e-mail, displays frequently asked questions and offers to decrypt the affected files. If the ransom isn't paid, the hacker warns that the information will be uploaded and monetized on the darknet. The same FBI report discouraged victims from paying the ransom and urged them to report the incidents to their local FBI field office.

Maricopa Community Colleges, following its incident response protocol, took its systems offline, including its e-mail, user portal, learning management system, student information system, human resources management system and Google tools. The college system also brought in forensic and recovery specialists to help determine what had happened and to resolve the outage.

By March 29, classes had resumed, and by March 30 the operating systems had been restored. However, the forensic review was continuing, and the school couldn't report on whether data had been stolen.

Moody's warned that the rise in cyberattacks had come at an especially vulnerable time for higher ed. Not only have "some university finances ... become more fragile because of revenue declines and expense pressures related to the pandemic," but also "university networks have expanded more than ever as instruction is carried out largely online and most staff and faculty work remotely."

Unexpected school and course closures damage customer relations, the briefing noted. There's also the financial hit, which poses a "growing credit risk for debt issuers": The average data breach cost for an education victim is $3.9 million, according to a 2020 Ponemon Institute study.

The full briefing, "US: FBI warning for universities underscores vulnerability to cyberattacks," is available to Moody's subscribers.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • glowing blue nodes connected by thin lines in an abstract network on a dark gray to black gradient background

    Report: Generative AI Taking Over SD-WAN Management

    In a few years, nearly three quarters of network operators will use generative AI for SD-WAN management, according to a new report from research firm Gartner.

  • abstract pattern with interconnected blue nodes and lines forming neural network shapes, overlaid with semi-transparent bars and circular data points

    Data, AI Lead Educause Top 10 List for 2025

    Educause recently released its annual Top 10 list of the most important technology issues facing colleges and universities in the coming year, with a familiar trio leading the bunch: data, analytics, and AI. But the report presents these critical technologies through a new lens: restoring trust in higher education.

  • abstract image representing AI tools for reading and writing

    McGraw Hill Introduces 2 Gen AI Learning Tools

    Global education company McGraw Hill has added two new generative AI tools to help personalize learning experiences for both K–12 and higher ed students, according to a news release.

  • abstract image of fragmented, floating geometric shapes with holographic lock icons and encrypted code, set against a dark, glitchy background with intersecting circuits and swirling light trails

    Education Sector a Top Target for Mobile Malware Attacks

    Mobile and IoT/OT cyber threats continue to grow in number and complexity, becoming more targeted and sophisticated, according to a new report from Zscaler.