Dear Fern Hill Parents, Vendors, Students and Alumni,
Some of you may have received a fraudulent email yesterday (Thursday, September 19th, 2024) between 1:24PM ET & 1:45PM ET that was sent out to many parents, alumni, staff and vendors of Fern Hill. We have concluded our investigation into the matter and are sending you this email to help answer any questions you may have.
What happened?
At approximately 11:39AM EST on Thursday, September 19th, 2024, our mail system detected a malicious actor originating in Buffalo, NY attempting to gain access to the secretary@fernhillottawa.com email address. While the attempt was successful, the intrusion detections we have in place disabled the account quickly, but not before the actor was able to, at 1:24PM, generate and send three(3) identical fraudulent emails with a subject line “Clearance letter & Confirmation of Attendance xcl” to a subset of parents, teacher’s personal email addresses and vendors (past and present). In total there were 632 recipients being addressed and at this time, it is unclear how many of those were delivered successfully to recipients, as many may have been flagged as spam or may have been rejected before getting delivered.
Due to the nature and speed of the attack, it has been determined that this attack was performed by a bot and not by a human. At this time, there is no indication that any other emails were viewed nor that any other data was obtained.
What do I need to do?
If you have received an email entitled “Clearance letter & Confirmation of Attendance xcl” from secretary@fernhillottawa.com, delete the email immediately. If you have clicked on a link or opened a document in the email, please reset your email password as soon as possible and perform a virus scan of your PC. If you did not click the link, then you are not affected by this phishing scam and no action is required by you.
What are we doing?
Fern Hill is taking this breach very seriously and has reset relevant passwords and refreshed all security protocols for this account. We will continue to monitor this account closely over the next few days to ensure there is no additional threat.
Fern Hill School takes your privacy and the privacy of our students very seriously and are aware that you may have further questions about Thursday’s email breach. If you would like additional information, please feel free to contact me via email (principal@fernhillottawa.com) or phone (613-746-0255).
Thank you for your patience,
Deborah Gutierrez
Principal
Fern Hill School