Moody's: Cyberattacks Could Dent Higher Ed Credit Rating

Cyberattacks could affect the financial standing of higher education as a business segment, according to a recent briefing by Moody's Investors Services. The "sector comment" came out shortly after two big security events, both occurring on March 16, 2021. First, the Federal Bureau of Investigation's Cyber Division issued a "flash" warning about an increase in ransomware targeting education institutions. Then, Maricopa Community Colleges, one of the largest community college systems in the country, discovered it had been hit by "suspicious activity" and, in response, brought its network down, pushing off the start of classes after spring break by a week. The announcement came on March 19, three days after the discovery.

The FBI report specifically alerted readers about PYSA ransomware, also known as "Mespinoza," which is "capable of exfiltrating data and encrypting users' critical files and data stored on their systems." Current targets include colleges and universities, K-12 schools and seminaries.

According to the report, PYSA gains its unauthorized access through compromised Remote Desktop Protocol (RDP) credentials and/or phishing e-mails. Once the data is pulled out, the systems — files, databases, virtual machines, backups and applications — are made inaccessible to users through encryption and the attacker demands ransom. The ransom message contains information on how to contact the criminal via e-mail, displays frequently asked questions and offers to decrypt the affected files. If the ransom isn't paid, the hacker warns that the information will be uploaded and monetized on the darknet. The same FBI report discouraged victims from paying the ransom and urged them to report the incidents to their local FBI field office.

Maricopa Community Colleges, following its incident response protocol, took its systems offline, including its e-mail, user portal, learning management system, student information system, human resources management system and Google tools. The college system also brought in forensic and recovery specialists to help determine what had happened and to resolve the outage.

By March 29, classes had resumed, and by March 30 the operating systems had been restored. However, the forensic review was continuing, and the school couldn't report on whether data had been stolen.

Moody's warned that the rise in cyberattacks had come at an especially vulnerable time for higher ed. Not only have "some university finances ... become more fragile because of revenue declines and expense pressures related to the pandemic," but also "university networks have expanded more than ever as instruction is carried out largely online and most staff and faculty work remotely."

Unexpected school and course closures damage customer relations, the briefing noted. There's also the financial hit, which poses a "growing credit risk for debt issuers": The average data breach cost for an education victim is $3.9 million, according to a 2020 Ponemon Institute study.

The full briefing, "US: FBI warning for universities underscores vulnerability to cyberattacks," is available to Moody's subscribers.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • NVIDIA DGX line

    NVIDIA Intros Personal AI Supercomputers

    NVIDIA has introduced a new lineup of AI-powered computing solutions designed to accelerate enterprise workloads.

  • interconnected glowing nodes and circuits in blue and green, forming a neural network on a dark background with a futuristic design

    Tech Giants Launch $100 Billion AI Infrastructure Network Project

    OpenAI, SoftBank, and Oracle have unveiled a new venture, Stargate, through which they aim to build a massive AI infrastructure network across the United States. The initiative, which was announced at the White House with President Donald Trump, has been described as the "largest AI infrastructure project in history."

  • college building with a central domed rotunda, arched windows, and columns, overlaid with glowing blue circuit patterns

    Kishwaukee College Moves to Ellucian Colleague SaaS

    Illinois's Kishwaukee College is modernizing its administrative systems with an Ellucian Colleague SaaS rollout that will bring AI-powered tools to human resources, finance, and student management.

  • The AI Show

    Register for Free to Attend the World's Greatest Show for All Things AI in EDU

    The AI Show @ ASU+GSV, held April 5–7, 2025, at the San Diego Convention Center, is a free event designed to help educators, students, and parents navigate AI's role in education. Featuring hands-on workshops, AI-powered networking, live demos from 125+ EdTech exhibitors, and keynote speakers like Colin Kaepernick and Stevie Van Zandt, the event offers practical insights into AI-driven teaching, learning, and career opportunities. Attendees will gain actionable strategies to integrate AI into classrooms while exploring innovations that promote equity, accessibility, and student success.