Ransomware attacks on secondary schools in England

The request was successful.

Dear Barking Abbey School, A Specialist Sports and Humanities College, Barking,

Please find below my FOI request regarding ransomware attacks on the school/college.

1. In the last 5 years, how many times has your school/college suffered from a ransomware attack? Please provide specific dates (months/years) if possible.
2. How much downtime did this cause (in hours)?
3. Did you pay the ransom? If so, how much was the ransom?
4. What type of ransomware was used?
5. What was the total cost of the incident to your school/college?
6. How many student and/or staff records were impacted in the breach?

If you don't have data available for all of the questions, please provide any data you do have.

We appreciate the sensitivity of disclosing ransomware attacks, which is why all of the data gathered will be anonymised in our final analysis and no individual schools or colleges will be mentioned.

Yours faithfully,

Rebecca Moody

Data Protection Enterprise - Info,

Dear Ms Moody

 

RE:  Freedom of Information Request – Barking Abbey School

 

Further to your request for information made on 22^nd January 2024 under
the Freedom of Information Act 2000 reproduced as follows:

 

‘1. In the last 5 years, how many times has your school/college suffered
from a ransomware attack? Please provide specific dates (months/years) if
possible.  

2. How much downtime did this cause (in hours)? 
3. Did you pay the ransom? If so, how much was the ransom? 
4. What type of ransomware was used? 
5. What was the total cost of the incident to your school/college? 
6. How many student and/or staff records were impacted in the breach?’

 

Section 1 of the Freedom of Information Act 2000 provides two distinct but
related rights of access to information which impose corresponding duties
on public authority schools. These are:

 

• The duty to inform the applicant whether or not information is held by
the authority and, if so, 
• The duty to communicate that information to the applicant

 

I can confirm that Barking Abbey School holds the information:

 

 1. In the last 5 years, how many times has your school/college suffered
from a ransomware attack? Please provide specific dates (months/years) if
possible.  0

2. How much downtime did this cause (in hours)? None 
3. Did you pay the ransom? If so, how much was the ransom? n/a
4. What type of ransomware was used? n/a
5. What was the total cost of the incident to your school/college? n/a
6. How many student and/or staff records were impacted in the breach? None

 

I trust you find the attached and above satisfactory.  However, if you are
dissatisfied with the handling of your request, then you have a right to
request an internal review. All such requests must be sent to us within 8
weeks and must clearly state the reason for your request for an internal
review. 

 

We will respond to your request for an internal review within 20 school
days of receipt. Your request for an internal review should be sent by
email to [1][email address]

 

Information Commissioners Office 

 

Should you remain dissatisfied with the final outcome of the internal
review then you may apply directly to the Information Commissioner for an
independent review. The Information Commissioner is the Government’s
Independent Body responsible for overseeing the Freedom of Information Act
2000, the Data Protection Act 2018 and The Environmental Information
Regulations 2004. Please note the Information Commissioner will only
review cases that have exhausted the school’s internal review procedure.
All correspondence to the Information Commissioner must include your
reasons for your appeal. The Information Commissioner contact details are
as follows:- 

 

The Information Commissioners Office, Wycliffe House,
Water Lane, Wilmslow,
Cheshire, SK9 5AF.
Tel: 0303 123 1113 

 

More information can be found at the Information Commissioner’s website
at [2]http://www.ico.org.uk  

 

Kind regards

 

Data Protection Enterprise Limited                              
email: [3][email address]

Tel: 07853091905 

 

References

Visible links
1. mailto:[email address]
mailto:[email address]
2. http://www.ico.org.uk
http://www.ico.org.uk/
3. mailto:[email address]
mailto:[email address]