Council took four days to identify cyber attack

News imageBBC A crescent-shaped building with flags at its front, while arches lead to its entrance. This is Bristol City Council pictured on a grey cloudy day.BBC
Bristol City Council said it acted immediately, as soon as it understood the threat

A local authority took four days to identify a cyber attack on the system it uses to manage the schools it runs.

Bristol City Council said it first noticed suspicious activity on the Trading with Schools service on 21 September but it was not shut down until 25 September.

The South West Regional Economic and Cyber Crime unit has confirmed that it is at the early stage of an investigation into the hack which has affected 87 schools.

Council leader Tony Dyer confirmed the discovery of malicious software. He said the council's current analysis had "not identified any evidence that data has been stolen".

Trading with Schools is a platform run by Bristol City Council and used by schools to manage day-to-day operations.

Schools across the city use it to varying degrees.

It can be used to give access to the internet for the purposes of scheduling, drawing up school budgets, recording staff details and payroll information.

The platform can also house sensitive information about children relating to educational psychology files.

Bath Spa University cyber crime expert Dr John Curry said one set of criminals could "farm" any data found and then sell it "in blocks to another criminal syndicate" which could weaponise it.

Blackmail was a major concern, he said, because of the personal information about teachers and sensitive data on pupils that the system contained.

He said hackers could also potentially manipulate orders of expensive equipment because the system contained details of schools' trading partners.

Dyer said: "As soon as we understood the nature of the threat, we took the decision to disconnect affected schools from the internet."

He said there was no evidence yet of mass data theft and "acting quickly helped us limit the spread of the malicious software".

Dyer explained there would be "some disruption" which was expected to continue for a period while schools were being issued with specialised devices to get them back online safely.

However, experts said four days was a long time for malicious software to be within a system.

Curry said hackers could delete logs to make it seem like nothing had been stolen, "like a burglar closing the front door".

News imageTony Dyer is pictured on a sunny day standing near a grassed area. There are pink flowers behind him and trees. He is an older man with receding grey hair and grey stubble. He is wearing a grey suit jacket, a lighter grey shirt and a grey and white spotted tie. He is also wearing glasses and is smiling widely.
Bristol City Council leader Tony Dyer said there was no evidence yet of mass data theft

Follow BBC Bristol on Facebook, X and Instagram. Send your story ideas to us on email or via WhatsApp on 0800 313 4630.