Vermont education officials face sophisticated phishing scheme this summer
Aug 19, 2026
Signs on a bank of computers tell visitors that the machines are not working due to a cyber attack. File photo by Tony Gutierrez/AP Photo
A number of Vermont school districts were hit with an insidious phishing scheme this summer, following a pattern of cybercriminals attacking crucial instituti
ons in rural communities.
“This is a really common hacking methodology, unfortunately,” said Denise Reilly-Hughes, secretary of the Agency of Digital Services. “Even the most skilled individual can become a victim because they can be very sophisticated. They can look very real. In this particular case it was directing folks to click on a link, and they did.”
It appears no student or staff data was stolen this time. But the scheme spread through real, trusted accounts, and serves as a preview of a threat that could reach any Vermonter.
Phishing is a form of digital fraud that aims to steal personal information such as usernames and passwords. State officials and technology experts warn that such credential theft is often just the first stage of a longer attack that can end in ransomware, fraud or a hijacked network, striking the rural school districts with thin cybersecurity defenses.
Brooke Olsen-Farrell, superintendent of Slate Valley Unified Union School District, said there has been a jump in these phishing schemes in the past month that exactly mimic a legitimate email.
Olsen-Farrell said that she and other Slate Valley staff clicked on an “excel secure portal” link in an email. That caused a script to run in the background of their accounts to read and delete emails and generate more phishing emails to their contact list, said Walter Ripley, technology coordinator for Slate Valley. There was no data compromised, as the district acted quickly, Ripley said.
Randy Rose, vice president of security operations and intelligence for the cyberthreat protection nonprofit Center for Internet Security, verified for VTDigger through cyberthreat intelligence analysis that the emails were credential-phishing attempts. Such emails are sent from real accounts to trusted contacts with an invented portal link, which serves to lure people into clicking and proliferating the scam further, Rose said.
Some educational leaders reported seeing phishing attempts from Vermont state emails that referenced state programs. However, there is no record of ingoing or outgoing phishing emails from state accounts, according to Reilly-Hughes.
The state identified the malicious software embedded in the header of the phishing emails and tracked the source to a Google Drive with an IP address based in Germany, Reilly-Hughes said in an interview last week. The cybercriminals may have just intended to cause disruption through collecting credentials — but also might have been seeking further sensitive information, said Reilly-Hughes. There has been no evidence of money exchange in this particular instance, she said.
“What we saw was that credential harvesting was only one part of the malware kill chain, but not the sole purpose of this exploit,” Reilly-Hughes wrote in an email last week. “This type of attack can be used to propagate other malware including ransomware or for use in a botnet campaign. I can’t make assumptions on the intent of this bad actor.”
Early-stage attack
Vermont is no stranger to cybersecurity attacks. Last year, dozens of Vermont school districts were impacted by a national data breach of a student information system. Earlier this year, Chittenden County Solid Waste District recovered more than $2 million after a cyberfraud incident.
READ MORE
Cybercriminals have increasingly targeted schools and other public sector infrastructure, especially in rural areas, because of their large budgets, limited cybersecurity resources and the critical nature of these community services, said Rose.
Credential phishing is often an early-stage attack that leads to further invasions, Rose said. The aim could be to trick workers into responding to seemingly legitimate requests from a known source to send money or share sensitive information. The goal could also be a ransomware attack, which locks people or institutions out of accounts and encrypts files until people pay to release their systems.
Jacquelyn Ramsay-Tolman, superintendent of Orleans Central Supervisory Union in the Northeast Kingdom, said she and other staff members of the supervisory union also encountered the “excel secure portal” email phishing scam that has been circulating in Vermont school districts this summer. But Ramsay-Tolman said the incident was addressed quickly before the network was compromised.
The supervisory union plans to change password policies for school accounts to ensure the district is protected from increasing cybersecurity threats, Ramsay-Tolman said.
“We are continuously monitoring our security measures as new threats emerge, and we are currently maintaining two-factor (authentication) for general users, multifactor for administrative personnel, and considering additional measures like physical security keys for all staff,” Ramsay-Tolman said.
The Consumer Assistance Program with the Vermont attorney general’s office did not receive any reports of this particular scam. Attorney General Charity Clark said in an interview last week that phishing schemes are more effective if scammers know information about someone, so it is important to implement a personal “data minimization policy” and keep accounts private.
“In today’s world, our data is something that’s at a premium, and also being used and collected by very legitimate companies, and it can make it difficult for the consumer to distinguish between what is legitimate and what is a scam,” Clark said.
When using multifactor authentication, Clark recommended avoiding the use of biometric data such as a face scan or voice recognition, because artificial intelligence technology can create synthetic images or sounds that mimic real people, called deep fakes. The proliferation of “edtech,” hardware and software services used by the education system, contributes to an increase in scam opportunities, Clark said.
Cybercriminals have many sophisticated tools these days, including QR codes, SMS messages and voice messages. Rose recommended that people use phishing-resistant multifactor authentication and verify the sender of messages before clicking any links or attachments. Phishing scams have kept evolving and continue to be effective because they take advantage of human trust, not just technology, he said.
“Slowing down is a really effective way to make sure you’re making the right decision, and you’re forcing your body to think critically about things in every walk of life,” Rose said.
How to avoid “shared a file” scams
Before you click:
Didn’t expect a file? Don’t open it.
Check the “To” line — is it really to you?
Verify with the sender by phone or text.
Never enter your password to “view” a doc.
Hover to preview a link; when unsure, don’t click.
Protect your accounts:
Turn on two-factor authentication.
Use a unique password for email.
Keep devices updated.
If you clicked:
Change your email password now.
Turn on two-factor authentication.
Tell your IT team or provider.
Watch for odd messages “from” you.
Report it:
Use your email’s “Report phishing” button.
File at ReportFraud.ftc.gov or ic3.gov.
Vermont: ago.vermont.gov/cap.
Sources: FTC (ReportFraud.ftc.gov), FBI (ic3.gov), Vermont AGO Consumer Assistance Program, Kent State SecureIT. CQ: reporting links verified Aug. 13, 2026; confirm VT AGO intake page before publication.
Read the story on VTDigger here: Vermont education officials face sophisticated phishing scheme this summer.
...read more
read less