We just received a tip that Seattle Public School students are using high-tech to steal teacher passwords, hack systems, and alter grades. I am waiting for SPS to confirm this.
According to an email sent by the district’s Chief Informational Officer Jim Ratchford at 11:15 a.m. today to SPS employees, including Interim Superintendent Susan Enfield, Department of Technology Services has determined that network log-in credentials “are being stolen and used to inappropriately access district systems.”
The email, whose subject line reads “Unauthorized Access Warning,” says that the incident “appears to have been going on for the last few weeks, possibly longer.” “At this point, we are aware of this happening at these schools: Ballard, Ingraham, and Sealth. However, all schools and teachers are at risk,” Ratchford says in his email.
More information on the hacking from Ratchford’s email, which was leaked to us by an anonymous SPS employee:
How is this happening? Someone is inserting a device called a “key logger” into computers — using a USB connection, a key logger is inserted into the computer’s USB port and the keyboard cable into the key logger. The key logger looks like the device below — similar to a keyboard or mouse wireless device or a flash drive and difficult to distinguish as out of the norm.
What does this mean to you?
1) What is happening: Teacher log-in passwords are being stolen and used to change grade book grades in Easy Grade Pro.
2) What do I do? Please check your desktop and/or your presentation computer for any unknown devices.
3) What do I do if I suspect my password has been stolen? Contact the TechLine at x20333 to identify your machine and log-in as compromised. They will help you change your passwords.
4) Check your students’ grades. Consider comparing EGP grades with the eSIS grades, and if they are different, it’s likely that your grade book has been compromised.Please — Do NOT use your username and password on a computer without first checking it for such a device.
We are exploring options to address this problem. At this point, the best mitigation is to visually check your computer for the key logger device.
Also, I need to emphasize that key logger devices capture all keyboard key strokes. Therefore, while the incidents we are experiencing appear to be focused on acquiring and using teacher log-in credentials, a key logger is also capturing: email messages, Internet URLs, personal accounts information (e.g. banking), etc.
If you have any questions, please do contact me and I or someone from the DoTS team will get back with you.
Jim
Jim Ratchford
Chief Information Officer
Seattle Public Schools
An SPS employee compared the whole unfortunate situation to “War Games, but not as cool.”

Fight the power!
Bueller? Bueller?
this is not a new issue, i first saw it in 1998 in middle school… the same old
My high school used an outdated version of Novell Netware. Let’s just say that you didn’t even need a keylogger to change those grades. This was in the early 2000’s.
At least they’re learning SOMETHING, right?
This is an interesting take (of course, that means I mostly agree with it) on cheating in schools and why it happens.
http://www.psychologytoday.com/blog/free…
@3, they didn’t have these fuckers in 1998.
It’s just a paywall.
Got r00t?
Doesnt need to be an external USB device, you can open up the case and connect it to the internal USB port. Can also run software that runs hidden in the background, logging everything and uploading it to wherever.
Checking the PC for USB dongles is kinda stupid, you need to check the whole PC, inside and out.
Whatever reporting you do, don’t refer to this as “hacking” or “hackers”. This is about as simplistic as it gets. (And the fact that the schools were unprepared for something like this should be a big, if not biggest part of the story.)
Take your pills, Will. You have to take them every day, remember?
Note that they sell these fucking things at SEARS, for chrissakes. Not exactly cloak and dagger stuff, is it?
SPSS needs to go to a token system, with a USB key. Something that you know, and something that you have.
Thank you @10.
If you want to learn more about the variety of hacking please see HackADay for your learning pleasure. For those even less interested in the technical hacking, don’t worry, you can enjoy LifeHacker!
Yeah, they were doing this all four years while I was at Nathan Hale High School.
Old news.
War Games? More like Ferris Bueller’s Day Off.
OH NO NOT THE HACKERS VERSUS CRACKERS DEBATE. SOMEONE DISTRACT THEM WITH A REN FAIRE OR A COPY OF THE HITCHHIKER’S GUIDE.
Half the time, the kids don’t even need a keylogger. They can just look under the keyboard for the sticky note the teacher wrote their password on. We had the same thing happen in our district about 10 years ago. The ringleader was one of the school board members’ kids. He was making some very tidy cash changing grades on request.
There was this one guy at my high school who got caught hacking into the school network. He didn’t actually do anything; he was just looking around places he shouldn’t. What happened to him? He was given six days of suspension, which he could take whenever he wanted, and which would not go on his permanent record. So basically they punished him by letting him cut class for six days.
@14: please explain why.
Ferris = changed absences.
War Games = changed grades.
Ferris’ antic was a reference to War Games
So how is this incident more Ferris than War Games?