THE ECHO
One story. Gone deep.
A small school district in Vermont found a ransom note on one of its servers. More than three weeks later, its school board voted, in public, not to pay.
Slate Valley serves six small towns in western Vermont. The note turned up on September 3. The internet went down, and so did district email and the students' Chromebooks. The phones worked. The schools opened. Everything else waited. The internet was out for nearly a week. It has since been restored.
The district worked with cybersecurity professionals, its lawyers, its insurance carrier and law enforcement. The FBI is investigating.
This past week, the board approved a motion "to decline to authorize payment of any ransom or extortion demand." Superintendent Brooke Olsen-Farrell wouldn't say how much was demanded, or how, or when, while the investigation continues.
Look at who made the decision. Not the security professionals. Not the lawyers. Not the insurer. Not law enforcement. The board, the people who answer to the families in those six towns.
Everybody else did the work. The board made the call.
The district did this well. It said what it could, and why it couldn't say more. It brought in help. And it made its decision in public, where the families could see it. That's a hard thing to do.
At a 40-person company, there's no board meeting. The board is you. Maybe a partner. Maybe whoever you'd call before signing something big. Or maybe it's nobody, and everyone assumes it's somebody else.
A school board meets on a schedule, has a process and answers in public. Your company probably doesn't work that way. If a ransom note turned up at yours, the call on whether to pay would most likely get made for the first time. In the middle of the crisis, with somebody else's clock running.
Picture that morning. The email's down. Your phone is ringing, and it's a customer. Your IT company is on the other line. Someone the insurer sent is asking questions. Everyone is waiting on one answer, from whoever they think is in charge.
Whether to pay is a conversation to have with your lawyer and your insurer. The question before that one: has anyone decided who decides? The worst week of your year is a bad time to find out who decides.
Start with something you've already bought. If you have a cyber insurance policy, pull it out. It probably says who to call first, and who the insurer will send. That help is real. At Slate Valley, everyone the district brought in helped. None of them cast the vote.
Ask your broker or your insurer, at renewal or sooner: "If we got a ransom demand tomorrow, who's in the room, what does the policy expect from us, and whose call is it to pay or not? Ours, or yours?" Whatever the answer is, you'll know it before you need it.
None of this needs a binder. It needs one conversation. Settle who decides on a quiet day. Then settle who that person calls first, and what they need to know before deciding. Your IT company belongs in that conversation, and so does whoever you'd call before signing something big.
Write the names down somewhere that still works when the email doesn't. A printed page works. So does a note in your phone.
Decide who makes the call before the call comes.
The details are from reporting by the Rutland Herald, ABC22 and DysruptionHub, September 29 and 30, including a statement from the district.
SIGNAL CHECK
What else matters this week.
The Badge on the Ad Blocker
Poper Blocker is an ad blocker for Chrome. More than 2 million people use it. It has 4.8 stars from 81,600 reviews, and it carried a "Featured" badge in Google's store.
Security researchers found it collecting the full address of every page its users visit. It also collects their conversations with ChatGPT, Claude and Gemini: what they typed, and what came back.
The instructions for what to collect come from the vendor's servers, so the vendor can change them without an update. The researchers say those instructions didn't arrive until about a day after install. They say the delay looks built to get past the store's review. Users get nagged until they agree to share data. It's listed for Microsoft Edge too, and the researchers confirmed the Edge version gets the same instructions.
Someone on your team added a browser add-on this year. Someone has probably pasted a client contract into ChatGPT, too. That's the kind of thing Poper Blocker was collecting.
The badge tells you it passed a check. It doesn't tell you when.
Ask your IT provider: "Can our people install browser add-ons on their own, and can you show me what's installed on our computers right now?"
The Invoice That Looks Exactly Right
Fakturownia is a Polish invoicing app that more than 600,000 businesses use. The company says someone got into its systems on September 27 and, over about a day and a half, copied a large part of its database. What they took includes bank account numbers, payment records, invoice amounts, and contact details for customers and suppliers. Card numbers and bank logins weren't stored there, and weren't taken.
The company warned its customers that fraudsters know the amounts and which invoices are unpaid.
That's everything someone needs to send a fake invoice that looks exactly right. The right supplier. The right amount. An invoice you really do owe. With one change: we've got a new bank account. The company told its customers to confirm any change of bank account by phone.
You don't use this app. Your suppliers probably use one like it. Whoever gets into theirs knows what you owe, and who you owe it to.
Ask your bookkeeper: "When a supplier says their bank details changed, who's allowed to change where we send the money, and what has to happen first?"
THE NOISE
Not every signal needs action.
The Teenager in the Headline
Police in nine countries, coordinated by Europe's police agency, Europol, took down a ransomware group called KillSec this past week. Its suspected leader, arrested in Spain, is 16. An arrest isn't a conviction. The group's servers were seized, along with the site where it named its victims. The Record, a news site that covers cybersecurity, reports the group is linked to around 1,000 attacks since 2024, at least half of them successful.
The age is what made the headlines. It won't change a thing you do on Monday.
The useful part is how the group got in, and it wasn't genius. The Record says the group "exploited vulnerabilities, especially in cloud storage." Europe's justice agency, Eurojust, points to "poorly secured access."
A group allegedly linked to that many attacks, often getting in through doors like those, isn't running anything clever. You don't need to out-think a sixteen-year-old. You need to not leave the door open.
Ask your IT provider: "Who can get into our cloud storage, and how is that locked down?"
ONE QUESTION
No answer. Just the question.
If a ransom note turned up on one of your servers tomorrow morning, who at your company would decide whether to pay? The harder part: do they know it's their call? Or would they find out that morning, along with everyone else?
Where to Start
The Echo's question takes one conversation. The Signal Score shows you which other conversations you haven't had yet.
It's a free set of plain-language questions about your company, including what happens when something goes wrong. It takes about fifteen minutes and shows where you stand before the worst week, not during it.
Prefer audio? Jane reads every Pulse edition on the Signal vs. Noise podcast. Five minutes, same signal, no scrolling. Find it wherever you listen.
Michael Faas is a fractional CTO/CISO who translates technical complexity into business decisions. echocyber.io

