Infosecurity Magazine reports that Washington State K-12 school district Highline Public Schools has acknowledged having had sensitive information from its students and faculty members stolen following a ransomware attack in September that resulted in the forced three-day closure of its campuses.
Infiltration of Highline's systems compromised not only individuals' names, birthdates, addresses, Social Security numbers, driver's license numbers, financial account details, employment data, passport numbers, digital signatures, health insurance information, and medical details, but also students' ID numbers, demographic information, grade details, and other records, according to a recently concluded investigation into the incident. "Additional security measures are being implemented to further protect against similar incidents moving forward. This incident was also reported to federal law enforcement," said Highline. Individuals affected by the breach, who have been given complimentary identity protection and credit monitoring services for a year, have been urged to track their credit reports and account statements for potential fraudulent activity.
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
The user, operating under the name Sadpainy, released code intended to replicate Stuxnet, the malware that reportedly destroyed a fifth of Iran's uranium enrichment centrifuges.
The malware, which has been active since at least 2023, adopted MQTT for its command-and-control (C2) communications in variants developed between 2024 and 2025, according to a report by Black Lotus Labs.