Aftermath of a Phishing Attack
February 01, 2024
Following a significant financial loss, the Atlanta Public Schools shares its story to motivate others to create safer cyber environments

In early September 2017, as Hurricane Irma was forecast by the National Weather Service to strike the metro Atlanta area, school districts across the region made quick plans to move to remote learning. Employees in the Atlanta Public Schools were asked to work from home to stay safe.
It was during that time that we started receiving phishing e-mails targeting thousands of our employees over several days. These e-mails took on several varied forms, all intended to lure our employees to “reset” their passwords. At the time, we already had a well-developed process in Atlanta for handling these phishing e-mails, and we swung into action to contain and address them.
Just as quickly as the e-mails landed in our inboxes, they suddenly stopped, and we thought we were out of the woods.
Compromised E-mails
September 29, 2017, should have been another ordinary day, a “payday” in the Atlanta Public Schools when the district’s 9,500 employees (including substitute teachers and hourly employees) were looking forward to receiving their paychecks for their hard work. Then, our payroll team started getting calls from employees who did not get paychecks. First, it was a handful of employees. When it was all said and done, 34 employees were missing paychecks.
As our technology team investigated, we quickly discovered the extent of the issues and were able to link them back to the phishing attacks. These employees had fallen for the fake password “reset” e-mails and had unknowingly provided their login credentials during the attack. The bad actors had compromised their e-mails and direct deposit accounts and had routed the paychecks to ghost debit cards. The money was gone.
We immediately engaged federal and local law enforcement agencies and hired cybersecurity experts to work alongside our team to determine the extent of the compromise. Our main goal was to enhance our protections and ensure the criminals had not compromised other critical systems. We worried that private information relating to employees and students had been exposed.
While this incident was financially motivated, it marked a significant turning point in our cybersecurity program. It helped us instantly get the attention and seriousness every program deserves in a K-12 school district.
Expensive Expertise
Every technology leader fears the day their informational and instructional technology systems will be the target of an outside attack. This fear cuts across all industries, from banking to energy production to health care and education.
In education, district leaders and chief information officers (where they exist) are responsible for implementing the systems, processes, people, and technology to prevent these intrusions. When posting jobs to hire cybersecurity engineers, district technology leaders need the resources to compensate knowledgeable and experienced staff. Competition for their skill sets comes from the private sector with its greater financial resources, making it harder to attract the best talent. District technology leaders operate at a disadvantage due to limited budgets.
While cybersecurity always had been considered necessary in the Atlanta Public Schools, the program did not receive nearly as much funding as in the year immediately following the attack, which was crucial in helping us invest significantly in our program.
Platform for Urgency
Security is not an exact science and often involves building layers around your critical assets and infrastructure to make it difficult for bad actors to attack those assets. Therefore, creating a safe cyber environment for schools involves a combination of technical measures, policies, and educational initiatives. These include (1) implementing robust network security; (2) securing personal tech devices of students, teachers and staff; (3) implementing user authentication strategies; (4) providing cybersecurity awareness training for students, teachers and staff; (5) updating software regularly; (6) securing Wi-Fi networks; (7) implementing data backup and recovery strategies; (8) developing incident response plans; (9) implementing Internet content filtering; (10) collaborating with law enforcement; (11) performing regular security audits; (12) implementing privacy policies; (13) involving parents and guardians; and (14) collaborating with informational technology professionals.
While it is expensive for schools to be proficient in all of these areas, the district’s tech leadership must work with superintendents to build a comprehensive cybersecurity program and prioritize the areas to be addressed first while working to improve other areas.
In Atlanta, the incident with the employee paychecks gave us a platform to advocate for urgent initiatives to be implemented immediately. Because we had an audience with the superintendent and chief financial officer, we could make the case for several technology tools to scan and filter our e-mail system for phishing attempts.
Collaborative Measures
Superintendents and their cabinet members can support their technology leaders in several ways before a cyberattack (preventative) and after an attack (curative).
Technology leaders will need their support to rally employees and students very quickly around any cyber initiatives that may be needed to counter or limit the impact of the attacks. District technology staff may be unable to do this themselves in the relatively short period it will be needed.
Collaboration also will be needed to develop short- and long-term budgets to address the immediate resource needs and build a sustainable program for years to come. We also requested additional funds to hire a cybersecurity firm to aid in the investigation immediately. While we ultimately did not use it, we had support from the superintendent and the chief financial officer to offer free credit monitoring should any employee learn his or her personal data was exposed. In the months following the incident, we worked with the budget team to fund other security measures.
While regularly providing status updates to our senior leadership, this experience also allowed us to collaborate with other internal division leaders. We worked with our chief human resources officer to incorporate cybersecurity awareness training into the annual ethics training required for all employees. We worked with the C-suite executives to enforce compliance with the cybersecurity training for all their employees. Our leadership team also consented to periodic “mock phishing” exercises where employees who failed to identify the potential threat would be enrolled in additional training.
Unknown to us then, several other school districts nationwide had experienced the same attacks we experienced in Atlanta. Because most of us don’t share cyberattack information openly, we had no opportunities to learn from other school districts (which might have prevented us from financial losses). As a result, we have made it our mission to share our story. We have since openly shared details of our attack with other school districts, especially our counterparts around Atlanta. The goal is to increase information sharing and learn from some of the best practice initiatives deployed across our state.
We see the Atlanta Public Schools case study as a compelling testament to the importance of a comprehensive and proactive approach to cybersecurity in K-12 education. School districts can bolster their defenses, mitigate risks and create a resilient cyber environment to benefit students, teachers and staff through continuous advocacy, collaboration and information sharing.
Olufemi Aina is the executive director of information technology for the Atlanta Public Schools in Atlanta, Ga.
Advertisement
Advertisement
Advertisement
Advertisement