Mayor Domenic Sarno addresses reporters at a Sept. 11 press conference about the cyberattack.
Reminder Publishing photo by Sarah Heinonen
SPRINGFIELD — In the wake of a cyberattack on Springfield Public Schools, the FBI has confirmed that the attack included a data breach. On Sept. 15, the School Department was notified that the data of students and staff was stolen.
On Sept. 1, School Department information technology staff noticed malicious signals on the school’s system. Over the next week, the staff worked to repel the cyberattack. City and school officials informed the public of the attack that weekend that they had been locked out of some computer systems and over the next week, began working to restore access.
In a press release on Sept. 15, SPS Chief of Communications Azell Cavaan said the extent of the stolen data is not yet verified, but it may have included staff social security numbers. The district does not keep student social security numbers in the system that was breached.
“The district has been working proactively since last week to expedite free credit monitoring services for all district personnel and remains committed to making that available as quickly as possible,” Cavaan said.
“Our priority remains supporting those who may be affected and working with our partners to understand the full scope of this incident. The district remains in close communication with state and federal law enforcement, legal teams and cyber forensics experts,” said Cavaan.
SPS has contracted IDX, a cybersecurity company that offers identity theft monitoring. Asked about the price tag attached to the credit monitoring services, Mayor Domenic Sarno said, “We’ll spend what we have to spend.” Superintendent Sonia Dinnall shared that when it experienced a data breach in 2020, IDX charged a certain dollar amount per employee. The School Department employs more than 4,800 people. The data breach also affects former employees.
In the 24 hours after SPS was notified about the breach, Cavaan said the School Department has been reaching out to families and staff. She said the website is being updated as information becomes available.
Considering why Springfield Public Schools may have been targeted, Dinnall said, “I’m just as baffled as anyone else.” She cautioned that data breaches are common and people should be “hypervigilant” in safeguarding their personal, identifiable information.
“The federal government needs to act on this.” Sarno said of the recent rash of municipal cyberattacks in Massachusetts. The city of Everett experienced a cyberattack the same day Springfield’s School Department was hit. On Sept. 16, the School Department in Sutton was attacked. In reaffirming his decision not to pay ransom demands in exchange for access to School Department systems, Sarno said, “You become an ATM … Once you give in, that knock at the door will come again.”
Reminder Publishing reached out to Springfield Education Association, the educators’ union, for comment but did not hear back by press time.


