School district reports malware attack

Parents attended Monday’s meeting of the trustees for Belgrade School District #44 to learn more about a recent malware attack.

Rumors had begun to circulate since an April 17 meeting where trustees authorized $750,000 to obtain network security and restoration services related to the attack. There was speculation that the money was to be used for a ransom.

Superintendent Dede Semerad said the $750,000 went toward restoring system functionality and preventing future incidents.

"The District maintains insurance for incidents of this nature and is working with its insurance carrier regarding reimbursement for these costs,” reads a Tuesday press release from the district. “Remediation funds are being used to restore functionality to affected systems and to strengthen the network environment to help reduce the risk of a similar incident in the future.”

As of Wednesday, the district’s investigation indicated the technology problems were caused by malware affecting certain systems within the district’s network environment.

“Upon discovery, the District initiated its incident response protocols, isolated affected systems, and took steps to secure, restore, and stabilize the network,” the release reads. “The District has eradicated the known malware from its network environment and continues working to remediate affected systems and return them to service. We anticipate this work will continue into June.”

District staff are working with cybersecurity experts to investigate the nature and scope of the incident, including whether any district data not maintained in the Infinite Campus system may have been affected.

“As part of that review, the District is conducting a detailed review of potentially affected systems and information to determine whether any personal information related to students, staff, or other individuals may have been involved,” the district said. “If the District determines that personal information was affected, it will identify the individuals whose information was involved and notify them directly. Any such notice will include information about the incident and available steps or resources to help individuals protect their information. Individuals who have concerns about protecting their information may review and use the resources previously circulated by the District.”

The district sent an email to families on Monday stating that its investigation hadn’t identified any evidence of unauthorized access to Infinite Campus, the cloud-based system that stores the district’s sensitive student data. The district also sent an email to families on April 6 reporting that the district "recently experienced technology issues affecting certain systems in our network."

"We have been working with our information technology staff and partners to look into the issues," reads the April 6 email. "Our assessment is in the early stages and is currently ongoing. In the meantime, we are working to repair our network systems to bring them back online in a quick, but safe manner."

The full April 6 email is available at https://tinyurl.com/4znwabm7. The full May 18 email is available at https://tinyurl.com/3avvwd4t.

Some of the parents who addressed trustees on Monday expressed frustration.

“We need transparency with the cyber-data breach, transparency with why the district is starting next year a million dollars in the hole and where that money went,” said parent Jake Feddes on Monday. “Transparency into why the administration is taking pay away from teachers and why our teachers haven’t had computers for the past month because they took them away because of the data breach.”

Personnel matters are private, Semerad noted Wednesday.

“The district is committed to maintaining employees' constitutional rights to privacy and cannot provide details regarding personnel decisions,” she wrote.

The district has been transparent about its finances, according to Semerad.

“The district provided extensive information to the public prior to the levy regarding the budget - that our budget is decreasing by $231,378 due to lower enrollment, and the district will need to fund contractual obligations already in place, including steps and lanes for our staff at a cost of $854,692,” Semerad wrote. “This was all in materials used during the levy campaign. The levy would have provided funding for steps and lanes as well as a percent increase to their wages. That was all in the details provided about the levy. It has also been discussed at publicly noticed board meetings, Finance Committee meetings, and negotiations meetings.”

Voters rejected a school levy a few weeks ago, and the district faces close to a $1 million budget shortfall for the upcoming school year.

A district source speaking anonymously told the Bozeman Daily Chronicle that teachers were kept “in the dark” about the cybersecurity issue that allegedly locked them out of school technology. The problem even affected teachers’ personal finances, the source alleged.

The source claimed that when Semerad was approached about a teacher’s bank account getting emptied after this data breach, Semerad said that was a coincidence. Semerad, responding Wednesday, said this is an inaccurate statement.

Semerad told the Chronicle that employees were reminded of the school's protocol for public statements and were asked not to speak on behalf of the district.

“What we don’t know is hidden behind claims of privacy, even when information could be shared responsibly,” said resident Steve Eaton during Monday’s meeting. “We’ve also heard that the details about the network issues and possible breaches have been kept from the public with staff instructed not to share details.”

Parent Eric Dighans, who spoke during Monday’s board meeting, didn’t believe the district’s initial explanation related to the malware incident. He criticized the “unprofessional” tone of the Monday email and indicated his concerns were not allayed.

“When we bring up the funding situation, eye contact goes away,” Dighans said to the board. “That shows me you guys are lying about something.”

Leslie Jensen addressed the board during Monday’s public comment period, speaking about transparency.

“Our community deserves clear and honest answers regarding the recent technology incident affecting our school district,” Jensen said. “Parents, staff members, and taxpayers have heard conflicting information. Some described it as a cyber-attack or hack while the district has avoided using those terms publicly.”

The district, in its Tuesday statement, sympathized that the malware attack has caused concern and that waiting for additional information has been frustrating for students, families, staff, and the broader community.

“The privacy and security of information maintained by the District is a top priority,” the district said. “Investigations of this nature require time because the District must carefully review affected systems and information before drawing conclusions, and the District is committed to completing that review carefully and accurately. We appreciate the community’s patience and will provide additional updates as appropriate.”