Finalsite Statement for the Media
Updated Sunday, January 10, 2022 at 6:30 p.m. Eastern Standard Time
The Finalsite security team monitors our network systems 24 hours a day, seven days a week. On Tuesday, January 4, our team identified the presence of ransomware on certain systems in our environment. We immediately took steps to secure our systems and to contain the activity. We quickly launched an investigation into the event with the assistance of third-party forensic specialists, and began proactively taking certain systems offline.
It is important to note that the ransomware is not what took our school websites offline. Our team of engineers did that proactively in order to protect client data. The team then began rebuilding websites in a new, secure environment.
In the ensuing time since the attack, our security, infrastructure, and engineering teams have worked around the clock to restore connectivity and bring our network back to full performance. We have been consulting with third-party specialists all along the way and brought systems back slowly and carefully to ensure the environment was safe and stable.
We have full access to our files and data. The forensic investigation is ongoing and at this time, we have no evidence that our data or client data has been taken. If we determine otherwise through the course of the investigation, we’ll act swiftly to notify clients and will take all appropriate actions.
Primarily, data and files stored by Finalsite are publicly-facing information found on school and district websites. Clients who use certain modules within our system also have demographic data stored in the Finalsite database, such as names, email addresses and phone numbers. Again, there is no evidence that any of this data has been compromised.
Finalsite does not transmit or store any credit card data. Finalsite does not store academic records, social security numbers or any other confidential information.
The investigation is still underway and could take weeks before completion. The remainder of the investigation is to confirm these findings and ensure compliance with applicable laws. Should there be variance in our findings through the remainder of the investigation, we will promptly inform clients and take appropriate next steps.