The Control Exists. The Proof Does Not. What a NJ School Ransomware Listing Teaches Every Business
A ransomware group listed a New Jersey school district on its leak site this week. The district has not confirmed anything. Both of those facts matter to every business owner reading this, and the second one matters more than it looks.
On September 2, 2026, Westfield Public School District appeared on the leak site run by the group known as INC Ransom. The listing gives an estimated attack date of September 1 (ransomware.live). The group’s posting claimed it would make sensitive district data public unless it was contacted for negotiation (DeXpose).
September 1 was also the first day of school in Westfield. Local reporting that day described district-wide phone and network outages, attributed to a networking hardware failure (TAPinto Westfield). By September 3, the outage was in its third day, affecting phones, internet, the student information system, and attendance. Superintendent Dr. Raymond Gonzalez said the district’s technology team was working with outside experts on an investigation still in its early stages, and that some systems would stay offline “until we are confident that they can be safely brought back into service” (Patch, September 3, 2026). That statement did not repeat the hardware-failure explanation, and it did not mention ransomware.
As of this writing, I have found no statement from the district connecting the outage to the leak-site listing, and no independent confirmation that an attack occurred.
So this is not a post about Westfield. It is a post about timing, evidence, and what an underwriter will ask any organization the week after a listing like this one appears. Everything below applies whether you run a school, a medical practice, an accounting firm, or a 40-person manufacturer in Middlesex County.
What we know, and what we do not
Here is the full set of facts, kept separate from interpretation.
A leak-site listing is a claim by a criminal group. It is not a breach notification, and it is not proof. Groups list victims to create pressure. Sometimes the listing is accurate. Sometimes it names the wrong entity, an old incident, or a vendor rather than the organization itself. Aggregators such as ransomware.live and the security firms that track them label these listings as unconfirmed for that reason.
What is confirmed: the listing exists, it is dated September 2, and the group claims to hold data. What is also confirmed: Westfield schools had a district-wide outage that began on opening day and ran at least three days; the first-day explanation was hardware, and by day three the district was describing an investigation with outside help and a deliberately cautious restoration.
Those facts sit next to each other. They may be unrelated. A careful restoration after a hardware failure is also what a well-run district does. If the district issues a statement, that statement is the record, and I will update this post.
I am writing anyway, because the situation is instructive regardless of how it resolves. The question a business owner should be asking is not “did it happen to them.” It is “if my name showed up on a leak site on the worst possible morning, what would I be able to prove by noon.”
Why the first week of school is the worst week
Attackers do not pick dates at random. They pick the week when the pressure to pay is highest and the capacity to respond is lowest.
For a school district, that week is opening week. Enrollment is live. Parent portals are live. Bus routing, lunch accounts, nurse records, and payroll for a new fiscal cycle are all running at once.
The people who could answer a technical question from an insurer are busy standing in hallways. A ransom demand that lands on September 1 lands on a district that cannot afford a day of downtime and cannot spare an hour to think.
Every business has an equivalent week. For an accounting firm it is the two weeks before a filing deadline. For a medical practice it is the Monday after a holiday. For a distributor it is the last week of a quarter.
If you know your worst week, so does anyone who has spent ten minutes reading your website.
The education sector shows what that pressure produces. Sophos’ State of Ransomware in Education 2026 report surveyed 226 IT and cybersecurity leaders across 17 countries between January and March 2026. Among lower education organizations hit by ransomware, the share whose data was actually encrypted more than doubled in a year, from 29% in 2025 to 61% in 2026.
The costs followed. Average recovery cost in education reached $2.26 million, against a cross-sector average of $1.7 million. About 26% of education institutions needed one to three months to recover, nearly double the 14% cross-sector figure. Among lower education organizations, 31% needed a month or more. The median ransom demand in education was $775,200.
Those are recovery figures, not ransom figures. They count the rebuild, the overtime, the outside counsel, the notification letters, and the lost weeks. A ransom, paid or not, is the smaller number.
The control exists. The proof does not.
Here is the pattern I keep seeing when I sit down with a school business administrator or a practice manager after an incident, or before a renewal.
The organization has backups. Nobody has run a restore test since spring, and nobody can produce the result of the last one.
The organization has multi-factor authentication. Nobody can export the enrollment report today, so nobody can say which accounts are actually covered and which have been quietly excluded.
The organization has endpoint protection. Nobody has written down whether it is watched at 2 AM on a Sunday or only during business hours.
In each case the control is real. The evidence is missing. And in the two rooms that matter most after an incident, the underwriter’s and the regulator’s, undocumented and absent look identical.
This is the same lesson behind why cyber insurance renewals are getting harder even as premiums fall. Marsh’s Global Insurance Market Index reported that cyber rates fell 4% globally and 2% in the United States in the second quarter of 2026. That was the twelfth consecutive quarter of declines. Insurers have capacity. What they no longer accept is a checkbox.
The friction has moved off the premium line and onto the evidence line. An incident is the moment that evidence is demanded on a deadline.
There is a court case worth knowing here. In 2022, after a ransomware attack at International Control Services, Travelers asked a federal court in Illinois to void the cyber policy it had issued. The carrier’s position was that the application had misrepresented the company’s use of MFA. The parties stipulated to rescission. The policy was declared null and void from inception, with no coverage available.
The company had paid its premium. What it could not do was prove the answer it had given on the application.
What the numbers say about schools and small organizations
A few more figures, each with its source, so you can weigh them yourself.
Sophos found that 85% of ransomware attacks against education institutions began with an identity-based technique, meaning stolen or abused credentials rather than a software exploit. Malicious email was the root cause in 31% of lower education attacks. In plain terms, most of these incidents start with a person’s login, which is exactly what MFA exists to stop and exactly what an MFA enrollment report proves or disproves.
Comparitech’s Education Ransomware Roundup for the first half of 2026 counted 104 attacks on education organizations worldwide, 36 of them confirmed. The United States accounted for 34, or 33% of the global total. K-12 attacks worldwide fell 26% from the second half of 2025. That is good news with a caveat: the median of the ransom demands Comparitech could identify rose 53% in the same period, to $420,620, though that median rests on a handful of publicly known demands.
Fewer attacks, bigger demands. And the ones that land are landing on organizations with less capacity to absorb them.
Outside education, Verizon’s 2025 Data Breach Investigations Report found ransomware present in 88% of breaches at small businesses, against 39% at large organizations. Coalition’s 2026 Cyber Claims Report found that business email compromise and funds transfer fraud together made up 58% of the cyber incidents it handled in 2025. Small organizations are not being skipped because they are small. They are being chosen because they are small.
New Jersey has already paid for this lesson
The Westfield listing is not the first time a New Jersey school system has been in this position this year. It is not even the most expensive.
In 2025, a criminal gained access to a Spotswood school district employee’s email account and used it to impersonate the board of education. The borough, believing it was dealing with the district, sent $4.8 million in local school tax funds it had collected for the district to the criminal instead, in two wires. About $1.7 million was recovered. As of spring 2026, roughly $3.2 million was still owed to the district, and the borough planned a short-term note sale to cover the gap, with an estimated cost of about $157 per average assessed home in the first year (Insurance Journal, reporting Bloomberg, April 30, 2026; Spotswood Borough public release, February 6, 2026). No ransomware was involved. No system was encrypted. One mailbox was enough.
That is the same mechanism behind the Coalition figure above: business email compromise and funds transfer fraud, 58% of incidents. An MFA enrollment report is the document that tells you whether your version of that mailbox is protected today.
The state has also been counting. NJCCIC logged 954 cybersecurity incident reports in 2025, a 92% increase over 2024 (NJ.com, March 23, 2026, as reported by Government Technology). In November 2025, New Jersey began paying $795,000 a year for a statewide MS-ISAC membership that gives eligible public organizations, school districts included, remote incident response, vulnerability scanning of public-facing systems, and monitoring of criminal forums at no cost to the organization. As of March 2026, 177 of 1,354 eligible organizations had signed up. That is 13%.
For comparison on the demand side: when LockBit claimed the May 2026 attack that closed Delano Public Schools in Minnesota for a day, the ransom demand was $1.2 million (Government Technology, August 2026). One day of closure, a seven-figure demand. The demand does not scale down with the size of the district.
If you sit on a New Jersey board of education and your district is not among the 177, that is a decision you can reverse this month at no cost. If you run a private business, the state membership is not available to you, but the services it bundles (monitored detection, restore testing, dark-web monitoring for your domain) are exactly what an underwriter now expects you to have arranged on your own.
What an underwriter asks the week after
Put yourself in the position of a school business administrator, or an owner, on September 3, the day after a listing appears. Your broker calls. The carrier wants to know whether this is a covered event and whether the application was accurate. The questions come in this order, and they come with a 48-hour clock.
When was your last full restore test, and what was the result? Not “we have backups.” The date, the scope, the time to restore, and who signed off.
Which accounts have MFA enforced, and can you show the enrollment report? Not “we use MFA.” The export, with the exceptions listed and explained.
Is your endpoint detection monitored around the clock, and by whom? Not the product name. The coverage hours and the escalation path.
Where is your written incident response plan, and when was it last exercised? Not “we would call our IT company.” The document, the contact tree, and the date of the last tabletop.
Who was notified, and when? The carrier, counsel, and for a New Jersey public school district, the state. Since March 2023, New Jersey law (P.L. 2023, c.19) has required public agencies, including public K-12 schools, counties, municipalities, and state agencies, and their government contractors, to report cybersecurity incidents to the New Jersey Office of Homeland Security and Preparedness, through its NJCCIC portal, within 72 hours of reasonably believing an incident has occurred.
If any of those answers takes more than a day to produce, that is your finding. Not the attack. The delay.
Two documents to ask for by Friday
I want to give you one action for this week, not a program. Ask your IT provider, internal or outsourced, for two documents by Friday.
The date and result of your last restore test. A restore test means someone took a backup and restored it to a separate system. They opened the files or booted the server. They recorded how long it took and what did not come back. A backup job that reports success every night is not a restore test. Ask for the date, the systems included, the time to restore, and the name of the person who verified it. If the honest answer is “we have never done one,” that is a better answer than a vague one, because now you have a starting point.
An MFA enrollment report for every account with a mailbox. In Microsoft 365 and Google Workspace this is an export, not a project. Microsoft Entra’s user registration details report lists every user, whether MFA is registered, and which methods are registered (it needs an Entra ID P1 license or higher). Google’s Security user report lists every user, whether 2-Step Verification is enrolled, and whether it is enforced. Neither shows everything in one place, but between the report and your enforcement policy the gap list takes an hour. Read it for two things. First, accounts with no MFA at all: shared mailboxes, service accounts, a former employee who was never fully offboarded. Second, accounts using SMS codes, which insurers such as Travelers and Corvus describe as less secure than an authenticator app. In a school, pay special attention to accounts that touch student information systems and payroll.
If either document takes more than a day to produce, you have learned something important before an underwriter or a criminal learned it for you.
The 30-day proof folder
Once you have the two documents, the rest of the evidence file takes about a month of ordinary effort. This is the same folder that makes a renewal painless, so it is not extra work. It’s work done once.
- Restore test log: date, scope, time to restore, verifier, and the gaps found. Repeat quarterly.
- MFA enrollment export: with every exception named and a reason written next to it.
- Endpoint coverage statement: which devices are protected, who monitors alerts, and during what hours.
- Backup architecture note: where copies live, which copy is offline or immutable, and who can delete it.
- Written incident response plan: one page is fine. Contacts, the first ten steps, and the notification list.
- Tabletop record: the date you walked through the plan with the people who would actually execute it.
- Vendor and application inventory: every system that holds student, patient, or client data, with the owner named.
- Insurance application copy: the answers you gave last time, so the next answers match the evidence.
- For New Jersey public schools and agencies: your MS-ISAC enrollment confirmation, and the NJCCIC reporting contact written into the incident response plan.
An organization with that folder does not scramble when a listing appears, and does not scramble at renewal either. The folder is the difference between an incident and a crisis.
What this means if you are not a school
Schools are in the headline because opening week is a visible pressure point. The mechanism is universal. Attackers pick the week you cannot afford to lose, and insurers ask for proof the moment you need coverage most.
For a CPA firm in Central Jersey that prepares tax returns, the equivalent is the FTC Safeguards Rule. It already requires MFA for anyone accessing customer information, encryption, a written incident response plan, and a written report to leadership at least annually. For a medical practice, it is HIPAA’s security rule and the breach notification clock. For a life sciences company, it is the vendor questionnaire from the larger partner that will not sign until the evidence arrives. In every case, the questions are the same ones an underwriter asks, and the same two documents are the place to start.
Where we can help
CMIT Solutions of Edison-Piscataway works with schools, professional services firms, medical and dental practices, and life sciences companies across Middlesex, Somerset, and Union counties. We run the restore tests, produce the enrollment reports, and build the proof folder so that the evidence exists before anyone asks for it.
If you run a school, a practice, or a firm in Central Jersey and want a second set of eyes on those two documents, call us at (732) 400-8577 or contact CMIT Solutions of Edison-Piscataway. We will tell you in one conversation whether your evidence would hold up, and what it would take to fix it if not.
Closing thought
The Westfield listing may turn out to be exactly what the district said on day one, a hardware failure and an unrelated criminal claim. Or the investigation the district described on day three may reach a different answer. I hope for the first. The lesson does not change either way.
The organizations that come through these weeks intact are not the ones with the most tools. They are the ones that can prove, on a bad morning, that the tools were on, tested, and watched.
Ask for the two documents. Start with the proof.
#K12 #NewJersey #RiskManagement#ManagedIT #Cybersecurity #NewJerseyBusiness #cmitsolutions #Ransomware #CyberInsurance #BackupAndRecovery #MFA #SmallBusiness
Sources
- ransomware.live, victim listing for Westfield Public School District (INC Ransom), discovered September 2, 2026, estimated attack September 1, 2026: https://www.ransomware.live/id/V2VzdGZpZWxkIFB1YmxpYyBTY2hvb2wgRGlzdHJpY3RAaW5jcmFuc29t
- DeXpose, “Incransom Targets Westfield Public School District,” September 2, 2026: https://www.dexpose.io/incransom-targets-westfield-public-school-district/
- TAPinto Westfield, “Westfield Public Schools Hit by Internet, Phone Outages First Day of School,” September 2026: https://www.tapinto.net/towns/westfield/sections/education/articles/westfield-public-schools-hit-by-internet-phone-outages-first-day-of-school
- Patch Westfield, “Phone, Network Outage Impact Westfield Schools During First Week Of School,” September 3, 2026: https://patch.com/new-jersey/westfield/phone-network-outage-impact-westfield-schools-during-first-week-school
- TAPinto Westfield, “Were Westfield Public Schools Hit by Ransomware? Here’s What We Know,” September 2026: https://www.tapinto.net/towns/westfield/sections/education/articles/were-westfield-public-schools-hit-by-ransomware-here-s-what-we-know
- Sophos, “The State of Ransomware in Education 2026,” August 2026: https://www.sophos.com/en-us/blog/state-of-ransomware-in-education-2026 and press release: https://www.sophos.com/en-us/press/press-releases/2026/08/identity-based-attacks-are-responsible-for-85-of-ransomware-in-education
- Comparitech, “Education Ransomware Roundup: H1 2026”: https://www.comparitech.com/news/education-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/
- Government Technology, “Ransomware Attacks on K-12 Trend Down, Higher Ed Trend Up in 2026”: https://www.govtech.com/education/k-12/ransomware-attacks-on-k-12-trend-down-higher-ed-trend-up-in-2026
- Marsh, Global Insurance Market Index Q2 2026, July 23, 2026: https://www.marsh.com/en/corp/about/news/global-commercial-insurance-falls-6-percent-q2-2026.html
- Verizon 2025 Data Breach Investigations Report, executive summary: https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf
- Coalition 2026 Cyber Claims Report, release of March 5, 2026: https://www.coalitioninc.com/claims-report/2026
- Travelers Property Casualty Co. of America v. International Control Services Inc., No. 22-cv-2145 (C.D. Ill.), as reported by Insurance Journal, August 30, 2022: https://www.insurancejournal.com/news/national/2022/08/30/682564.htm
- Insurance Journal (Bloomberg), “Cyberattack on NJ School Forces Debt Sale to Cover Stolen Funds,” April 30, 2026 (Spotswood): https://www.insurancejournal.com/news/east/2026/04/30/867738.htm
- Spotswood Borough, “Public Release February 2026 Update,” February 6, 2026: https://www.spotswoodboro.com/post/public-release-february-2026-update
- Related CMIT post, “Why Cyber Insurance Renewals Are Getting Harder for SMBs”: https://cmitsolutions.com/piscataway-nj-1178/blog/why-cyber-insurance-renewals-are-getting-harder/
- Government Technology, “New Jersey Sign-Ups for MS-ISAC Remain Low Amid Attacks,” reporting NJ.com, March 23, 2026: https://www.govtech.com/security/new-jersey-sign-ups-for-ms-isac-remain-low-amid-attacks
- NJCCIC MS-ISAC statewide membership page: https://www.cyber.nj.gov/grants-and-resources/partner-resources/ms-isac
- New Jersey P.L. 2023, c.19 (72-hour cyber incident reporting), approved March 13, 2023: https://pub.njleg.gov/Bills/2022/PL23/19_.HTM and NJCCIC incident reporting: https://www.cyber.nj.gov/report/incident-reporting
- Corvus by Travelers, “Best Practices for Multi-factor Authentication”: https://www.corvusinsurance.com/resources/cybersecurity-101/multi-factor-authentication-guide
- Microsoft Learn, Entra authentication methods activity and user registration details: https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-methods-activity
- Google Workspace Admin Help, Security user report: https://knowledge.workspace.google.com/admin/reports/user-reports-security
- FTC Safeguards Rule business guidance: https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know