Jump to content

Recommended Posts

Posted

Sorry for the title it's not clickbait! Please read to the end.

 

So further to by post below that didn't really get much traction I thought I would start a new thread and post it here so it has a wider audience. Firstly to recap, the school uses Cypad where the teacher marks the dinner registers. Cypad gets the school student list from SIMS and is synced on a regular basis.

 

On January 27th a teacher reported the dinner register for her class has had the names changed but by the time I looked all was well and nothing out of place. The teacher then said they had taken a photo of the screen and on inspection some of the names had indeed been changed to rude or offence names.

 

I immediately reported this to Parentpay and the asked for an update the next day and was told it has been escalated to the technical team. After not hearing anymore I asked for an update again on February 2nd but didn't get a reply until February 11th and then it took another email to remind them I was waiting for an update. The reply said the technical team are still investigating.

 

As we are dealing with names of students I cannot show the photo but the names had been changed so someone who might be called Jane Smith was changed to Diarrhea Jane or someone who might be Mohamed was changed also but I better not go into that any further. 

 

I contacted our SIMS support people who investigated if SIMS had been changed which it had not so they opened a case with Parentpay only to be told as the data is correct in SIMS the changes didn't come from SIMS and to contact Cypad!

 

Cypad users cannot changed the data it uses on the dinner registers so where else could it have been changed?

 

 

Posted
7 minutes ago, tom_newton said:

Any chance it was something local to that teacher's device?

No teachers or admin cannot edit the cypad data is taken directly from sims which is why the name changes had disappeared when I looked because a sims to cypad had taken place over writing any changes 

Posted
30 minutes ago, itskdog said:

Is it web-based? Could be a child who knows how to use the browser developer tools (Right-click -> Inspect Element)

Cypad is web based but this is a primary so none of the students here could do that. It was viewed on the teachers machine and the teachers class is foundation so I’m sure that age students couldn’t do it  

Posted

Also sounds like the type of defacement is too... adult.. for your students. TBH, I would still think a more local issue likely - particularly as it seemed localised, and went away fast. @itskdog makes an excellent point - is there another adult in the area who might have done this as a prank?

Posted
5 minutes ago, tom_newton said:

Also sounds like the type of defacement is too... adult.. for your students. TBH, I would still think a more local issue likely - particularly as it seemed localised, and went away fast. @itskdog makes an excellent point - is there another adult in the area who might have done this as a prank?


It was only the class teacher who is also the assistant head and the family support officer in the room. It was around 8:45 when it was found so students were still coming in and I think it’s more likely the refresh from SIMS cleared the corruption. 
 

ParentPay are being very slow with their updates and although I have asked to be given the contact details of their technical team so I can ask directly the info is not forthcoming, that alone makes me suspicious. Someone said they are waiting for it to blow over, perhaps they are right. 

Posted
7 hours ago, tom_newton said:

One of those things where you are at the mercy of the vendor now - as the evidence has been overwritten. Good luck, and keep us posted!


Yes but we still have the photo as evidence!

  • Like 1
Posted

If ParentPay had been hacked I don't think any hacker would use their access just to troll a random school by changing some pupil names ?  To me it definitely sounds like something a primary pupil would have done.  How though I've no idea 

Posted

Would you believe it. I have two threads running with similar titles and I posted my reply in the the wrong thread.

 

I am not saying it was a hacker of the type we are used to hearing about but more of a mischievous person who should know better and had this happened to another school I would be saying the same as you are anyway I had an update from parentpay. I was on leave yesterday but saw it on my phone but as the screenshot of the logs were too small to read I waited until I was back in today to go any further with it.

 

So they have sent screenshots of the logs and say it was a member of staff who made the changes only the member of staff who they have identified is the office manager and I don't think for one moment that is true. Not only that on the logs at the time in question is after the incident occurred. I'll paste their email and my reply but have to remove the screenshots of the logs and staff name.

 

 

  Quote

Good morning xxxxx,

We have successfully replicated the issue and confirmed the root cause. The issue occurred when a user updated a pupil’s nickname via the UI.

This action caused the pupil’s first name to be overwritten on the Whiteboard display.

 

Following our log review, we identified the user who made the changes:

 

Name: xxxxxx xxxxxx
Email: [email protected]
Username: xxxxxxxx

 

A screenshot has been attached showing the logs of those actions.

 

 

  Quote

Good morning,

Thank you for the email which was very interesting and if I am reading it correctly it indicates xxxxx xxxxx’s logon was used to change the pupil’s name on the display however I should point out that the email has numerous errors that I will list below.

 

1. It was not just the first name that was altered it was both first and last name.
 

2. In this screenshot and outlined in red it does indeed show xxxxx xxxxxx’s UserGuid however the time of the bottom line highlighted in blue is after the incident occurred and not only that it shows a internal address that is not accessible publicly (10.30.192.12) and certainly not from our school. This IP address is most likely used inside your network. Our public address is shown on the top line highlighted in green and is the day after the incident.


As a reminder the incident was first spotted at 9am on the 27th January 2026.

We request this is investigated further and escalated to a more experienced member of your team.    

Thank you for your understanding.

 

 

I had another email this morning saying the case has been resolved.

Posted

I wonder, is there any integration set up that might use the office manager's email as creds?

 

The time thing is hard to fathom, as we're UTC at the moment, so it's not a UTC vs BST thing...

Posted
4 hours ago, tom_newton said:

I wonder, is there any integration set up that might use the office manager's email as creds?

 

The time thing is hard to fathom, as we're UTC at the moment, so it's not a UTC vs BST thing...


AFAIK even with the admin creds I couldn’t alter the student names. Perhaps there is a way but it wasn’t immediately obvious. 


On the 2nd bullet point the IP address was an internal address but more importantly the time was over 6 hours after the incident was spotted so really shouldn’t have been included in the evidence. Some people may not have looked closely at the time or IP address and been fobbed of by this. 

Posted

My immediate thoughts were an inspect element prank. But if that 10.30.192.12 IP address is not part of your network are you looking at a compromise of the office account?

 

Have you got MFA configured (if it's available)?

 

Is there any chance office is used on other systems with the same password that could have had a compromise elsewhere?

 

If it's pointing to not being an internal prank, you need to start working on the assumption of a security incident with a bad actor having access to your systems potentially both internally and externally.

 

Sending a communication to staff outlining that it will be investigated as such and asking for any information might flush out someone trying to have a laugh and be a good opportunity to de-escalate the situation.

 

In the meantime, check out the office managers PC for any apps that you don't manage/recognise and get them to change their passwords as a belt and braces first steps.

  • Like 1
Posted

Thanks good advice but before I start pointing the finger I need a more accurate time of when the data was changed. The office manager’s account was a red herring and I say that because the time given for that logon was around 6 hours after the ‘hack’ was spotted so I would like earlier data from the logs as no point giving me logon data after the event has taken place. 

Posted

As you've identified an unknown IP, it could be using the local timestamp at the client end, which could be someone in a different time zone.

What are the regional settings on your devices?

Posted

We use uk time but anyway the logging would use local time and not the connecting device time.

 

The IP address was an internal address not a public address

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...