The learning management platform used by universities suffered a breach involving names, email addresses, student ID numbers and user messages. After the company chose to patch rather than negotiate, the group responsible caused an outage displaying a ransom note to every user. The disruption hit final exam periods at some institutions.
The chosen moment isn't coincidental and describes the attack's logic. Academic systems have brutal seasonality: during exam week, every hour offline carries an institutional cost that doesn't exist in July.
The decision to patch rather than negotiate deserves recording, because it's the standard expert recommendation and is rarely followed when pressure mounts. Its cost appeared as visible retaliation, and it remains the decision that doesn't fund the attacker's next operation.
The type of data exposed is what worries in the medium term. Names, institutional emails and student IDs form the basis of any later targeted scam aimed at students, an audience typically untrained to recognise fraud.
For anyone running systems with known seasonality, the practical lesson is about calendars: reviewing exposure and testing recovery off-peak is cheap; discovering the flaw during the peak costs a year of reputation.
