Live data from Hacker News

Illinois college, hit by ransomware attack, to shut down

nbcnews.com

41–50 of 89 posts

Re: Illinois college, hit by ransomware attack, to shut down

#41
post #14

Hey, I actually have experience with that school! I did some consulting with them about a decade ago. The ransomware attack certainly didn't help, but it is wildly misleading to say, or even imply that caused them to shut down. The actual reasons: (a) They filled a niche that didn't need to be filled anymore. They used to absorb students from other local universities (ISU, UIS, UIUC). Those schools have realized the…

> Lincoln College is scheduled to close its doors Friday, becoming the first U.S. institution of higher learning to shut down in part due to a ransomware attack.

In the first paragraph it's saying in part.

The article also details other challenges they face. We'll never know if they would have found a way to address these challenges and survive long-term had this not happened.

Re: Illinois college, hit by ransomware attack, to shut down

#42
“Lincoln College was a victim of a cyberattack in December 2021 that thwarted admissions activities and hindered access to all institutional data, creating an unclear picture of Fall 2022 enrollment projections,” the school wrote in its announcement. “All systems required for recruitment, retention, and fundraising efforts were inoperable."

How is this possible? There's literally not a second copy of the data anywhere? The people working in the admissions office didn't have a printout and they had absolutely no idea what the numbers looked like? It's one thing to have all the videos for online classes get locked up in a ransomware attack, but this simply cannot be true.

Re: Illinois college, hit by ransomware attack, to shut down

#43

Nations should lessen the penalties for white-hat and even grey-hat hackers who report their findings. They should have strong protections; they are helping all of society and national security. Instead, we have politicians and executives who make legal threats to cover their mistakes and everyone suffers for it. I have this view because I have personally walked away from security problems I've discovered simply by p…

> Nations should lessen the penalties for white-hat and even grey-hat hackers who report their findings. Digital Good Samaritan laws.

There's an overlap between privacy, civil liberties, and anti-discrimination concerns where laws that can be selectively enforced get disproportionately applied to any and all groups that have 'isms' attacking them.

I confess that while I used to spend quite a deal of time thinking about this class of problem, I haven't done much of it recently, so the following is a mix of potentially outdated thoughts and speculative nonfiction.

If you have the privilege to be outside of any or all of those groups, I feel like it falls on us to speak up to ensure that other people are okay, and Good Samaritan laws can be problematic in this respect, because it's too easy to convince a jury to deny 'those people' standing.

I wondered in another response if some sort of self-reporting system would better serve this space. Possibly 'feature-parity' with other citizen-action laws where community policing and reporting are carried out. The latter closes out a learning opportunity however because you're identifying and reporting a suspicion of an issue and allowing The Authorities to look into it. "We will take it from here." doesn't afford you the opportunity to become part of 'we'.

Perhaps there's precedent with confidential informant laws, and we need to reframe white hat hackers under that umbrella.

Re: Illinois college, hit by ransomware attack, to shut down

#44
post #14

Hey, I actually have experience with that school! I did some consulting with them about a decade ago. The ransomware attack certainly didn't help, but it is wildly misleading to say, or even imply that caused them to shut down. The actual reasons: (a) They filled a niche that didn't need to be filled anymore. They used to absorb students from other local universities (ISU, UIS, UIUC). Those schools have realized the…

> Lincoln College is scheduled to close its doors Friday, becoming the first U.S. institution of higher learning to shut down in part due to a ransomware attack. In the first paragraph it's saying in part . The article also details other challenges they face. We'll never know if they would have found a way to address these challenges and survive long-term had this not happened.

[deleted]

Re: Illinois college, hit by ransomware attack, to shut down

#45
post #15

"Fortunately, no personal identifying information was exposed." How can they know this?

Maybe the database that was stolen had none? I know my old community college just used a pin for everything. Maybe all the data tracks to this pin and then another database contains the pin to real name/info mapping? Hopefully personal information at a college has stricter regulation.

In this case the pin is the person identifying date. If such a database system was used at place and in time of the incident, it is known how many individuals are affected and what data got out.

It is just not known which individuals in specific.

Should be common to send a notice to all individuals then and explain the details so those who are affected do know and can act.

Re: Illinois college, hit by ransomware attack, to shut down

#46
We were looking at "cyber insurance" for our college and found out that we would be disqualified because every network connected device (even those on isolated networks) needs to have 2FA. Well, we have a network connected CNC machine at it has no provision for it. Another institution has the same machine and was denied. They tried every a lot of gyrations but got nowhere. Even a previous security audit would not help.

I get the feeling this is one of those rules setup to make sure they don't deal with small institutions with small IT departments or they really don't know how much the cost of insurance to them will be.

Re: Illinois college, hit by ransomware attack, to shut down

#47
post #15

"Fortunately, no personal identifying information was exposed." How can they know this?

They might have outsourced their enrollment system like a lot of smaller colleges to the vendor (e.g. Empower, Jasmine) and not have had the information on servers that were compromised.

Re: Illinois college, hit by ransomware attack, to shut down

#48

We were looking at "cyber insurance" for our college and found out that we would be disqualified because every network connected device (even those on isolated networks) needs to have 2FA. Well, we have a network connected CNC machine at it has no provision for it. Another institution has the same machine and was denied. They tried every a lot of gyrations but got nowhere. Even a previous security audit would not hel…

That rule would apply to larger IT depts too, though, right?

Re: Illinois college, hit by ransomware attack, to shut down

#49

The headline is clickbate. According to the article it says it closed due to COVID and the attack.

Yes, but at the same time, an experienced consumer of headlines should parse this syntax as "Illinois college to shut down. Illinois college hit by ransomeware attack, as well." (i.e., despite weaving the two things together, causation isn't actually claimed).

I don't like it, but it's been the nature of the headline game since long before clicks.

Re: Illinois college, hit by ransomware attack, to shut down

#50
post #48

We were looking at "cyber insurance" for our college and found out that we would be disqualified because every network connected device (even those on isolated networks) needs to have 2FA. Well, we have a network connected CNC machine at it has no provision for it. Another institution has the same machine and was denied. They tried every a lot of gyrations but got nowhere. Even a previous security audit would not hel…

That rule would apply to larger IT depts too, though, right?

I would imagine they are in a better position to negotiate and have the resources to make strict rules the insurance company would like.
Post reply on HN