Mobile County School System Fends Off Two Cyber Attacks During Testing WeekMobile County School System Fends Off Two Cyber Attacks During Testing Week

The Mobile County Public School System weathered two separate denial-of-service cyber attacks this week that briefly knocked out internet access during standardized testing and a school board meeting, according to district technology officials. The attacks arrived on consecutive days at the worst possible moment for a district in the middle of computer-based testing, and they offered one of Alabama’s largest school systems an unscheduled lesson in the realities of running a modern digital infrastructure in public view.

Chief Information Officer David Akridge said the attacks, which hit Tuesday and Wednesday, were traced to servers with IP addresses in China and on the West Coast of the United States, though he cautioned the attacks may not have actually originated in those locations. The caveat reflects a basic truth of cyber forensics: attack traffic is routinely bounced through machines around the world, and the address a flood appears to come from rarely identifies whoever is behind it.

Unlike high-profile breaches at companies such as Sony Pictures and Target, Akridge said no firewalls were breached and no personal information, including student records, was accessed or stolen. The distinction between an attack that breaks in and one that merely clogs the front door defined the district’s experience, and it is the reason officials could describe the episode as a disruption rather than a breach.

“We feel like right now we have it fixed,” Akridge said, adding that he was proud the system’s defenses held. The resilience he described was not accidental: the district’s network team spent the interval between the two attacks hardening the same connections the first attack had tested.

How the Attacks Worked

According to Akridge, the attacks flooded the district’s firewall with a barrage of automated traffic, effectively overwhelming its internet connection rather than penetrating internal systems. Denial-of-service attacks do not steal anything; they bury a network under more requests than it can process, in the way a prank caller can tie up a phone line without ever saying a word. For a school district whose testing platform, attendance systems and communications all ride on the same connection, the result is that legitimate work simply cannot get through.

He said the first attack Tuesday appeared aimed at probing for vulnerabilities, while Wednesday’s attack seemed designed to exploit any weak points identified a day earlier. That progression, reconnaissance followed by a targeted second strike, suggested a deliberate actor rather than random malicious traffic, though tracing the source conclusively is a task that typically involves federal partners and rarely produces a public answer in school district cases.

See also  Extra Security and Orange Bollards Frame Mobile's Pride-Themed June Art Walk

Each disruption lasted about 30 minutes, but the timing proved troublesome: schools throughout the county were in the midst of ACT Aspire standardized testing, one of the only computer-based testing rollouts in the state. The ACT Aspire assessment moved Alabama’s annual testing program substantially onto computers, which meant that a district’s internet connection had become, for a stretch of spring days, part of the state’s testing infrastructure. When the connection dropped, tests in progress dropped with it.

Susan Smith, who oversees the district’s research and accountability office, said students at roughly 72 schools experienced some kind of disruption during testing. The scale, spread across schools throughout the district rather than concentrated in a few buildings, mirrored the structure of the network itself: every school’s connection passes through the same central choke point the attackers targeted.

District officials said no student will be penalized for incomplete tests as a result of the outages, and staff are coordinating with the Alabama State Department of Education to give affected students another chance to finish. The reassurance addressed the fear most likely to reach parents: that minutes lost to an outage would become scores lost to an incomplete test, and that those scores would follow their children into placement and accountability decisions.

Akridge said the precise number of schools with affected computer labs was hard to pin down but confirmed it was significant across the system. Testing windows are scheduled by building, and the attacks struck while labs throughout the district were in use, so the disruption map changed hour by hour as schools entered and exited their testing blocks and the network recovered between blows.

The episode is a reminder of the vulnerability school districts face as more instruction and testing shifts online, even for systems that do not typically consider themselves prime targets for hackers. A school district’s network carries student records, payroll, communications, instructional platforms and, during testing season, the state’s assessment program itself. That makes it valuable enough to attack and, for the people responsible for it, too essential to leave unhardened.

See also  Mobile, Baldwin Counties Receive Nearly $3.9 Million in Federal Homelessness Grants

The comparison Akridge drew to Sony Pictures and Target served a purpose beyond scale. Both corporate breaches became shorthand for data theft: movies and customer card numbers exposed by attackers who got inside. The Mobile County attacks inverted that pattern. Nothing got inside, nothing was taken, and the damage consisted entirely of connectivity, the resource a computer-based testing program cannot function without.

For a district the size of Mobile County’s, the largest school system in Alabama, network administration is an industrial-scale undertaking. Hundreds of schools and facilities connect through district infrastructure to the internet, thousands of testing devices depend on that connection during assessment windows, and a small technology staff is responsible for keeping the whole structure available on days the calendar has fixed months in advance. The attacks chose their moment well, which is precisely why the district treated them as deliberate.

The response now embedded in the district’s playbook includes the fixes Akridge described and the coordination with state education officials over make-up testing. Districts that experience denial-of-service attacks typically emerge with updated traffic filtering, better monitoring and a clearer sense of which systems must survive an outage and which can wait. Mobile County’s version of that lesson cost two thirty-minute interruptions and a scramble of rescheduled testing, a modest tuition for an education in network defense that many districts have since studied.

The school board meeting caught in the disruption illustrates how far a district’s dependence on its network extends beyond the classroom. Board meetings stream, document and vote on systems that ride the same infrastructure as the testing platforms, so when the connection buckled, the interruption reached the governance of the district itself. What would once have been a matter of chalk and paper is now a matter of bandwidth, and the people who run Alabama’s largest school district felt that change in real time.

Denial-of-service attacks have grown into a commodity in the years since districts first connected their schools to the internet. Tools that flood a target with traffic circulate widely, and the motive spectrum runs from bored teenagers testing their skills to extortionists who promise relief for payment. School districts occupy a peculiar place among targets: they hold sensitive data but rarely pay ransoms, they are public institutions whose disruption is visible, and their networks are busiest on schedules everyone can read, including the attackers.

See also  After 38 Years, Mobiles Christmas Town Closes Its Doors for Good

The choice of testing week for both attacks suggests whoever launched them understood that schedule. Alabama’s assessment calendar is published, the hours when computer labs fill are predictable, and the damage an outage does is greatest when the state’s testing program is midstream. Whether the timing was calculated or coincidental, the district treated the two-day pattern, probe then exploit, as evidence of intent rather than accident.

The cooperation with the Alabama State Department of Education on make-up testing reflects the structure of state assessment, in which every enrolled student is expected to complete the exam and districts are accountable for participation and completion rates. An outage that leaves a classroom’s tests incomplete is not treated as the students’ failure, and the make-up process exists precisely for circumstances like a network outage no school could have prevented.

Teachers and test coordinators absorbed much of the immediate burden. A thirty-minute outage in the middle of a testing session means proctors managing restless students, logging which tests were interrupted and following the district’s instructions on resuming or rescheduling. The teachers’ handling of those minutes is part of why the district could report that no student would be penalized: the record of what happened in each room came from the staff who kept order through it.

What Akridge called having it fixed amounts to a district that has seen its network attacked twice in two days and has adjusted accordingly. The firewall held, the records stayed sealed, the tests were rescheduled rather than sacrificed, and the system that operates dozens of schools across Alabama’s most populous county returned to the business of the school year. The attackers, wherever they actually were, taught a lesson the district will not forget: in a school system that runs on its network, the network is now part of the infrastructure of public education itself.