A local authority took four days to identify a cyber attack on the system it uses to manage the schools it runs.
Bristol City Council said it first noticed suspicious activity on the Trading with Schools service on 21 September but it was not shut down until 25 September .
The South West Regional Economic and Cyber Crime unit has confirmed that it is at the early stage of an investigation into the hack which has affected 87 schools.
Council leader Tony Dyer confirmed the discovery of malicious software. He said the council's current analysis had "not identified any evidence that data has been stolen".
'Ageing without children can be hard and lonely'
'Ageing without children can be hard and lonely'
'My girl lost her limbs to meningitis - get the jab'
'My girl lost her limbs to meningitis - get the jab'
Man in court after 'explosive substances' found
Man in court after 'explosive substances' found
Trading with Schools is a platform run by Bristol City Council and used by schools to manage day-to-day operations.
Schools across the city use it to varying degrees.
It can be used to give access to the internet for the purposes of scheduling, drawing up school budgets, recording staff details and payroll information.
The platform can also house sensitive information children relating to educational psychology files.
Bath Spa University cyber crime expert Dr John Curry said one set of criminals could "farm" any data found and then sell it "in blocks to another criminal syndicate" which could weaponise it.
Blackmail was a major concern, he said, because of the personal information teachers and sensitive data on pupils that the system contained.
He said hackers could also potentially manipulate orders of expensive equipment because the system contained details of schools' trading partners.
Dyer said: "As soon as we understood the nature of the threat, we took the decision to disconnect affected schools from the internet."
He said there was no evidence yet of mass data theft and "acting quickly helped us limit the spread of the malicious software".
Dyer explained there would be "some disruption" which was expected to continue for a period while schools were being issued with specialised devices to get them back online safely.
However, experts said four days was a long time for malicious software to be within a system.
Curry said hackers could delete logs to make it seem like nothing had been stolen, "like a burglar closing the front door".
Follow BBC Bristol on , X and Instagram . Send your story ideas to us on email or via WhatsApp on 0800 313 4630 .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
