Lexington-Richland 5 won’t pay ransom following breach

Posted 8/29/25

Lexington-Richland School District Five Superintendent Akil E. Ross said the district will not be paying hackers a ransom who disrupted operations in June. 

While an investigation is still ongoing into the breach, Superintendent Akil E. Ross, along with Jack Jupin, a security expert, provided more insight on the incident. 

This item is available in full to subscribers.

Subscribe to continue reading. Already a subscriber? Sign in

Local news from Lexington's only local news source. Subscribe today.

You can cancel anytime.
 

Please log in to continue

Log in

Lexington-Richland 5 won’t pay ransom following breach

Posted

Lexington-Richland School District Five Superintendent Akil E. Ross said the district will not be paying hackers a ransom who disrupted operations in June. 

While an investigation is still ongoing into the breach, Ross, along with Jack Jupin, a security expert, provided more insight on the incident. 

Before the meeting, community members were able to submit questions to the district and have them answered during the forum. 

On June 3, the district detected “unusual network activity." Ross said the district noticed they lost access around 6 a.m. that morning and followed their cybersecurity protocol.

The district's technology team began investigating the incident with help from law enforcement and third-party specialists. The team then began restoring the affected files.

Jupin said these cyberattacks are common, and around 70% of Americans have already experienced their information being compromised. 

Ross said the district will implement training and hardware systems to the network to prevent a breach from happening again. The names of the security hardware and software are being withheld for security reasons.

He also mentioned safeguards already in place, including filtering students’ emails unless they come from known addresses. Jupin noted that teachers and administrators also need to be careful about what they open and click.

“People are too quick sometimes to just click, and it takes one person to open that door and your whole system is exposed,” he said. 

Both Jupin and Ross, however, said this cybersecurity breach was not intentional, and called it a “phishing scam.”

Jupin added the “actors” attacked the district for money. He said scammers often move on to another target without looking at the personal information they got.

Ross said the district declined to pay the ransom. Jupin agreed, saying he advises his clients to not pay as well. “If you pay, it just perpetuates the problem,” he said. “Now they wait six months and do it again, because maybe you’ll pay the second time.”

While the district does not store Social Security numbers for current students and families on their networks, former students' personal information, including names, dates of birth, addresses and Social Security numbers, had been posted online in a forum.

Those affected will be offered credit monitoring and identity theft protection. These services will also be offered to the current staff,  although officials say there is no confirmation their information is at risk.

Ross said the district insurance will cover 12 months of protection, but will be extended if additional material information is compromised. 

While the investigation continues, district officicals said they are hopeful it will determine how the attacker gained access to the information. 

For additional questions, email lexrich5securityincident@lexrich5.org. 

Comments

No comments on this item Please log in to comment by clicking here