← All incidents
Resolved, last updated 2022
K-12 districtVice Society ransomwareLeaked VPN credentialsWe will not pay

LAUSD Vice Society Ransomware

September 2022. The marquee K-12 ransomware case of its era. The second-largest US district refused to pay, and the gang published 500GB of stolen data, setting a precedent other districts now weigh.

What happened

The Vice Society gang accessed the Los Angeles Unified School District's network using leaked VPN credentials, stayed inside for more than a month, then published about 500GB of stolen data after the district refused to pay. LAUSD is the second-largest US school district, serving roughly 600,000 students.

Confirmed exposed

  • Contractor and employee Social Security numbers, names, and home addresses
  • Payroll and labor records, passport data
  • Folders labeled "Secret and Confidential"

Confirmed not exposed

  • LAUSD stated the most sensitive student psychological evaluations were not in the released set, though scope assessment continued

Why it belongs in this library

The biggest district, federal attention, and a clear "we will not pay" decision. Whether or not to pay a ransom is now a question every district board should have an answer to before it is asked under pressure.

Sources

  1. BleepingComputer — LAUSD says Vice Society ransomware gang stole contractors SSNs (2022)
  2. TechCrunch — Hackers leak 500GB trove of data stolen during LAUSD ransomware attack (2022-10-03)

This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].

LAUSD Vice Society Ransomware: September 2022 | Ask Before You App