Connect with us

E-Business

Ransomware: ESET Alerts Schools, Offers Remedy

Published

on

esset.jpg
Kindly share this post

It can often feel like every day brings news stories about ransomware attacks on businesses, particularly at hospitals and schools.

While the life-or-death nature of hospital data might force some healthcare organizations to accede to criminals’ demands in hopes of restoring access to that data as quickly as possible, some schools are also falling prey to these demands.

Paying criminals is never a good idea, even when it seems expedient. Ransomware authors are under no obligation to actually give you what you pay for, and there have been plenty of cases where either the decryption key did not work or the ransom note never even appeared.

Suffice it to say that cybercriminals are not generally renowned for their excellent software testing or devotion to quality customer service.

There are plenty of things that you can do now that will help you avoid a school ransomware problem entirely, and there are even a few things you can do that might help repair the damage so you don’t have to fork over ransom money.

Advertisement

What Makes Schools Unique?
In a way, schools are like small cities: they often have healthcare clinics, stores, restaurants, sometimes even banks, plus they have accountants, administrators, etc.

They have various types of company and personal financial data, healthcare information, student and staff records – all of which are very sensitive and thus very lucrative to criminals.

Ransomware is a special situation within malware, where data are not necessarily exfiltrated from a victim’s system (as with other kinds of modern malware). Instead, access to that data is interrupted. If you’ve ever had to deal with the disquiet of a student or teacher under deadline, you know that while timely access may be less a matter of life and death than in a hospital, it’s still absolutely crucial in a school.

And while hospitals are fairly limited as to which devices are approved to enter the network, schools generally encourage their users to bring their own devices.

This brings a higher level of challenge, as an untold number of unmanaged machines are connecting to the network each day.

Advertisement

What can you do about it school ransomware
Let’s start with the things you can do in advance to help prevent malware from getting on your system in the first place, and to minimize damage if it does happen.

Back Up Your Data
The single most important thing you can do to prepare for emergencies, including being affected by ransomware, is having a regularly updated and secured backup. Many ransomware variants will encrypt files on drives that are mapped.

This includes any external drives such as a USB thumb drive, as well as any network or cloud file stores to which you have assigned a drive letter. So your backup needs to be on an external drive or backup service, one that is not assigned a drive letter, and that is disconnected from your systems and network when not in use.

Keep Your Software Up To Date
Malware authors frequently rely on people running outdated software with known vulnerabilities, which they can exploit to get onto your system unobserved. It can significantly decrease the potential for malware infection if you make a practice of updating your software often.

Enable automatic updates if you can, update through the software’s internal update process, or go directly to the software vendor’s website. Malware authors sometimes disguise their creations as software update notifications, so by going to known to be good software repositories you can increase the odds of getting clean, vetted updates.

Advertisement

On Windows, you may wish to double-check that old – and potentially vulnerable – versions of the software are removed, by looking in Add/Remove Software within the Control Panel.

Use A Reputable Security Suite
It is always a good idea to have both anti-malware software and a software firewall to help you identify threats or suspicious behavior. Malware authors frequently update their creations to try and avoid detection, so it is important to have both layers of protection.

If you run across a ransomware variant that is so new that it gets past anti-malware software, it might still be caught by a firewall when it attempts to connect with its Command and Control (C&C) Server to receive instructions for encrypting your files.

Use the Principle of Least Privilege
The Principle of Least Privilege says that no users or systems should have more access than is necessary to complete tasks that are legitimately within the scope of their work.

As a general rule, most users should not have administrative rights on their machines, and should be limited in their ability to access resources outside of their own purview.

Advertisement

Students should have different access levels than teachers, who should have different access than administrators. Personal devices brought from home should also be treated differently from machines that always remain within the school network. If appropriate barriers are in place, you can slow or halt the spread of malware.

Educate Your Users
While accidents do happen, it is important for all of your users to understand what acceptable use of school resources entails. This is something that should not just be done once at the beginning of the year and forgotten by the time midterms come around. It should be an exercise that is revisited frequently.

Posters or other educational materials can be displayed prominently, wherever public computers or internet connections are available. It is also imperative to encourage your users to let you know when an accident has occurred, so that damage can be limited by quick corrective action.

Rewarding safer security behaviour, including pointing out problems, can help you to foster an encouraging environment.

The next few tips are to help you deal with the methods that current ransomware variants have been using – these tips may not help in every case, but they are inexpensive and minimally intrusive ways to cut off access routes used by a variety of malware families.

Advertisement

Disable Macros in Microsoft Office Files
Most people may not be aware that Microsoft Office Files are like a file system within a file system, which includes the ability to use a powerful scripting language to automate almost any action you could perform with a full executable file. By disabling macros in Office files, you deactivate the use of this scripting language.

Show Hidden File-Extensions
One popular method malware uses to appear innocent, is to name files with double extensions, such as “.PDF.EXE”.

This takes advantage of default behaviour within Windows and OS X of hiding known file-extensions, Malware takes advantage of this behaviour to make a file appear to be one that would commonly be exchanged. If you enable the ability to see the full file-extension, it can be easier to spot suspicious file types.

Filter EXEs in email
If your gateway mail scanner has the ability to filter files by extension, you may wish to deny emails that arrive with “.EXE” files, or to deny emails sent with files that have two file extensions, the last one being executable (For example, “Filename.PDF.EXE”). If you do legitimately need to exchange executable files within your environment and are denying emails with “.EXE” files, you can send them within ZIP files or via cloud services. Sending in ZIP files can also give you an extra layer of assurance, as it allows you to choose an official, universal password for use within the company, which can help you identify unofficial files.

Disable files running from AppData/ LocalAppData folders
You can create rules within Windows or with Intrusion Prevention Software, to disallow unique behaviour often used by ransomware, which is to run its executable from the App Data or Local App Data folders. If you have legitimate software that you know is set to run from the App Data area (note that this is fairly unusual behaviour, and most legitimate software will allow you to choose another install location), you will need to add an exclusion from this rule.

Advertisement

Disable RDP
Ransomware malware sometimes accesses machines using Remote Desktop Protocol (RDP), which is a Windows utility that allows others to access your desktop remotely. If you do not need use of RDP in your environment, you can disable it to protect your machines. For instructions on how to do so, visit the appropriate Microsoft Knowledge Base article below:

Windows XP; Windows Vista; Windows 7; Windows 8; Windows 10
If you find yourself in a position where you have already run a ransomware executable without having taken any of the previous precautions, your options are more limited. There are a few things you can still do that might help mitigate the damage:

Check to see if a decryptor is available
Sometimes malware authors make mistakes and decryptors can be created. Other times, malware authors feel remorse for their actions or stop development on a particular ransomware family, and then release a decryption key. It’s worth a quick internet search to see if the solution to your problem is available for free, from a reputable source.

Disconnect from WiFi or unplug from the network immediately
If you run a file that you suspect may be ransomware, but you have not yet seen the characteristic ransomware screen, if you act very quickly you might be able to stop communication with the C&C server before it finishes encrypting your files. If you disconnect yourself from the network immediately you might decrease the number of files that it can encrypt.

Use System Restore to get back to a known-clean state
If you have System Restore enabled on your Windows machine, you might be able to take your system back to a known-clean state. Many ransomware variants will prevent this from succeeding, but it doesn’t hurt to try.

Advertisement

Set the BIOS clock back
Some ransomware variants have a payment timer that increases the price for your decryption key after a set time. You may be able to give yourself additional time by setting the BIOS clock back to a time before the deadline window is up.

Criminals know that the data under the care of schools are very valuable to students and staff, and this makes them a potentially lucrative target. And once a target has been identified as vulnerable, the odds increase that criminals will return to attack them again (especially with school ransomware). By taking the time to prepare before an emergency happens, you can minimize the risk of losing access to your data or of having to pay criminals to regain it.

 Lysa Meyers is ESET security researcher

 
 

Advertisement

Kindly share this post

Nigeria CommunicationsWeek believes that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. So since 2007, we have devoted our energy to independent reportage of technology and how they affect lives.

Continue Reading
Advertisement
Comments

E-Business

Jumia Nigeria Expands Flexible Payment Options with Klump Partnership

Published

on

Kindly share this post

Jumia Nigeria, the country’s e-commerce platform, has introduced a new instalment payment option on its marketplace through a partnership with Buy Now, Pay Later (BNPL) provider Klump, giving customers another way to pay for purchases without bearing the full cost upfront.

The new option allows eligible customers to spread payments for selected purchases over a period of up to 12 months after making an initial deposit of between 20 and 30 percent. The partnership is expected to widen access to products such as smartphones, electronics, home appliances, and other everyday essentials for consumers who may prefer structured repayment plans over one-time payments.

Customers selecting the option at checkout can compare financing offers from participating financial institutions, complete a digital credit assessment, and, once approved, begin repayment through fixed monthly instalments. The introduction of instalment payments comes as digital commerce continues to evolve in Nigeria, with retailers exploring payment options that respond to changing consumer spending patterns and the growing demand for financial flexibility.

Commenting on the partnership, Chief Executive Officer of Jumia Nigeria, Temidayo Ojo, said the initiative reflects the company’s commitment to making online shopping more accessible to a wider range of consumers.

“We are constantly looking at practical ways to remove barriers to online shopping. For many customers, affordability is not always about the price of a product but about having payment options that fit their financial reality. By introducing instalment payments with Klump, we are giving customers greater flexibility while making quality products more accessible.”

Advertisement

He added that expanding payment choices forms part of Jumia’s wider effort to improve the overall customer experience and support the company’s ambition of becoming Nigeria’s everyday retail destination.

“Whether we are strengthening our logistics network, expanding product selection, or introducing new payment solutions, the goal remains the same: to make shopping on Jumia simpler, more convenient, and more accessible for customers wherever they are,” Ojo said.

Founded to simplify access to goods across Africa, Jumia has continued to invest in technology, logistics, and payment solutions to make digital commerce easier for consumers in both major cities and emerging markets across Nigeria.

The addition of instalment payments complements the range of payment methods already available on the platform and comes at a time when consumer demand for flexible financing options is increasing across the retail sector.

Celestine Omin, Co-founder and Chief Executive Officer of Klump, said the partnership aligns with Klump’s objective of expanding access to responsible consumer credit.

Advertisement

“When we started Klump, our mission was simple: to give Nigerians access to affordable credit wherever they shop. Today, we’re pleased to partner with Jumia to bring flexible instalment payments to one of Africa’s largest e-commerce marketplaces, making it easier for more customers to access the products they need,” Omin said.

Under the arrangement, Klump will provide the financing infrastructure while customers complete the application process digitally during checkout. Financing offers are provided through participating financial institutions, subject to approval.

For Jumia, the partnership represents another step in expanding the range of services available on its marketplace while supporting broader efforts to deepen digital commerce and financial inclusion. As more Nigerians turn to online shopping, the availability of flexible payment options is expected to lower one of the barriers to e-commerce adoption, particularly for higher-value purchases.

Customers can access the instalment payment option by selecting Klump at checkout on eligible products available on the Jumia platform.

Advertisement

Kindly share this post
Continue Reading

E-Business

Lagos Unveils N10m Single-digit Loan Scheme for MSMEs

Published

on

Kindly share this post

The Lagos State Government has launched a new financing initiative that will provide single-digit interest loans of up to N10 million to micro, small and medium enterprises (MSMEs), in a major push to improve access to affordable credit and stimulate business growth across the state.

The initiative, known as the Lagos State Access to Finance for SMEs through Cooperatives (LASMECO) programme, offers eligible businesses loans at a fixed 9 per cent annual interest rate, with repayment periods of up to 36 months for term loans and 24 months for working capital facilities. Beneficiaries will also enjoy moratoriums of six months and three months respectively.

The scheme was unveiled on Monday during the opening of a three-day LASMECO Accelerator Training Workshop organised by the Ministry of Commerce, Cooperatives, Trade and Investment, in Lagos.

In her keynote address, the Commissioner for Commerce, Cooperatives, Trade and Investment, Mrs Folashade Bada Ambrose-Medebem, said the programme was designed to bridge the financing gap facing thousands of Lagos businesses that have been priced out of conventional lending because of high interest rates and stringent collateral requirements.

Ambrose-Medebem, represented by the Director of Cooperative Services, Adeyinka Adeyemi, noted that MSMEs account for about 80 per cent of employment and contribute roughly 75 per cent of Lagos State’s Gross Domestic Product (GDP), yet many struggle to access affordable credit as commercial lending rates range between 35 and 40 per cent.

Advertisement

According to the commissioner, LASMECO addresses the challenge by using registered cooperative societies as financial intermediaries and guarantors, allowing entrepreneurs to obtain loans without relying solely on conventional collateral.

Under the financing framework, she said borrowers will provide 10 per cent cash collateral, while their cooperative societies will guarantee 25 per cent of the loan, adding that Sterling Bank Plc would provide a 50 per cent guarantee, creating a layered risk-sharing structure that makes lending more accessible and sustainable.

The programme targets businesses in agriculture, manufacturing, healthcare, the digital economy, creative industries, tourism, environmental sustainability and education.

The commissioner disclosed that the Lagos State Government has released its counterpart funding, while the Bank of Industry (BOI) has matched the state’s contribution, paving the way for loan disbursement, saying that BOI would serve as co-funder and final loan approver, while Sterling Bank would process applications, conduct credit assessments, disburse funds and recover repayments.

The commissioner reaffirmed the Lagos State Government’s commitment to ensuring the success of the initiative, expressing confidence that the programme would unlock affordable financing for thousands of entrepreneurs while boosting employment, productivity and economic development across the state.

Advertisement

Earlier, the Permanent Secretary in the ministry, Mr Babatunde Onigbanjo, said the workshop marked the transition of LASMECO from policy to implementation, stressing that the programme was fully funded and ready for rollout.

He said all necessary groundwork had been completed, including the release of counterpart funding, execution of memoranda of understanding and onboarding of accelerator organisations, adding that participants were now being equipped to begin recruiting and preparing loan beneficiaries.

According to him, the three-day workshop is designed to prepare accelerator organisations to identify eligible MSMEs, assess their credit readiness, compile loan applications and support borrowers from application through disbursement and repayment.

Onigbanjo urged participants to focus on quality rather than quantity in recruiting loan applicants, warning that poorly prepared businesses could increase loan defaults and undermine the programme.

He stressed that accelerator organizations would only be paid when the businesses they support successfully secure funding, saying the arrangement was intended to align their interests with the success of the programme.

Advertisement

The permanent secretary also emphasised that every loan applicant must belong to a registered cooperative society, describing the cooperative model as central to the programme because cooperatives provide a 25 per cent guarantee for every facility while helping to formalise informal businesses.

He disclosed that Lagos has more than 13,000 registered cooperative societies, although only about 1,900 to 2,200 are currently active, adding that reviving dormant cooperatives would significantly expand access to the financing scheme.

Onigbanjo warned accelerator organizations against charging applicants processing, training or evaluation fees, stressing that the only approved deductions are a N200,000 accelerator support fee and a one per cent BOI appraisal fee, both payable only after successful loan disbursement.

He said the state would closely monitor loan recovery, business growth, job creation, cooperative compliance and portfolio performance, adding that only accelerator organisations that deliver strong results would remain in the programme.

The permanent secretary described LASMECO as more than a loan scheme, saying it is also a strategy to formalise businesses, strengthen cooperatives, promote industrialization and drive inclusive economic growth across Lagos.

Advertisement

He urged participants to make full use of the workshop to prepare for immediate enrolment of qualified businesses, insisting that the programme had moved beyond planning and was now ready for implementation.

 

Kindly share this post
Continue Reading

E-Business

SERAP to Sue NASS over Bill Empowering NDPC to Regulate Social Media

Published

on

Kindly share this post

Socio-Economic Rights and Accountability Project (SERAP) has threatened to drag the National Assembly to court over a proposed amendment to the Nigeria Data Protection Act, which it alleges could indirectly empower the government to shut down social media platforms in Nigeria.

SERAP to Sue NASS over Bill Empowering NDPC to Regulate Social Media

SERAP, which made the threat in an open letter to Godswill Akpabio, Senate President, and Tajudeen Abbas, speaker of the House of Representatives, urged them to immediately reject and withdraw the Nigeria Data Protection (Amendment) Bill, 2026, sponsored by Senator Ned Nwoko (APC, Delta North).

The civil organisation described the proposed legislation as a “backdoor attempt” to regulate social media and expand government control over online expression.

It further warned that if the bill is enacted in its current form or a substantially similar one, it would “promptly take all appropriate legal actions” to challenge its legality in the public interest and protect the fundamental rights of Nigerians.

The bill seeks to compel social media platforms, data controllers, and data processors operating in Nigeria to establish physical offices in the country.

Advertisement

It further empowers the Nigeria Data Protection Commission (NDPC) to shut down or prohibit the operations of any entity that fails to comply within 30 days.

SERAP, in the letter dated July 18, 2026 and signed by Kolawole Oluwadare, deputy director, SERAP, argued that the proposed powers could enable an administrative agency to impose what would effectively amount to a nationwide restriction on digital communication without adequate judicial or procedural safeguards.

“The Bill constitutes a backdoor attempt to regulate social media and increase governmental control over online expression through corporate localisation requirements rather than through transparent and constitutionally permissible regulation,” the organisation said.

It also maintained that the proposed localisation requirement could increase government leverage over technology companies, facilitate political pressure, and make censorship demands easier to enforce.

SERAP further warned that requiring companies to establish local offices could expose their employees in Nigeria to retaliation.

Advertisement

The organisation said the proposed amendment could affect millions of Nigerians who rely on digital platforms to exercise their rights to freedom of expression, access information, associate with others, participate in political life, conduct business, pursue education, and engage in civic advocacy.

SERAP particularly criticised the proposed power of the NDPC to prohibit entities from operating in Nigeria after a 30-day period of non-compliance.

It said the bill contains no requirement for prior judicial authorisation, no obligation to consider less restrictive alternatives, and no meaningful safeguards to assess the impact of a prohibition on the fundamental rights of millions of Nigerians.

“In effect, the Bill empowers an administrative agency to impose sanctions comparable to a nationwide restriction on digital communication without the procedural guarantees ordinarily required whenever fundamental rights are at stake,” it said.

SERAP argued that the proposed provision could not withstand scrutiny under Section 45 of the Nigerian Constitution, which permits restrictions on fundamental rights only when prescribed by law, pursued in the pursuit of a legitimate aim, and reasonably justifiable in a democratic society.

Advertisement

While recognising the government’s legitimate interest in ensuring that digital platforms comply with Nigerian law, the organisation contended that such regulation must meet the constitutional criteria of necessity and proportionality.

“There is no evidence that existing powers under the Nigeria Data Protection Act are inadequate, that current enforcement mechanisms have failed, or that less restrictive alternatives would be insufficient,” it stated.

SERAP further cautioned that the proposed legislation could recreate the repercussions of the Federal Government’s suspension of Twitter, which the ECOWAS Court of Justice previously criticised

In SERAP and Others v. Federal Republic of Nigeria, the regional court ruled that the Twitter suspension infringed rights to freedom of expression, access to information, and media freedom protected under the African Charter on Human and Peoples’ Rights.

Although the proposed amendment differs from the Twitter suspension, SERAP argued that it might produce a similar outcome indirectly by empowering regulators to bar digital platforms from operating in Nigeria.

Advertisement

“The National Assembly should not enact legislation capable of producing, through indirect regulatory means, the very restrictions on fundamental rights that regional human rights law prohibits,” the organisation emphasised.

It also cited Section 39 of the Nigerian Constitution, Article 19 of the International Covenant on Civil and Political Rights, and Article 9 of the African Charter, as securing freedom of expression and access to information.

SERAP maintained that international human rights standards mandate restrictions on freedom of expression to be lawful, necessary, proportionate, and the least intrusive means available to achieve a legitimate public goal.

The organisation additionally warned that mandatory localisation requirements could undermine Nigeria’s digital economy and innovation ecosystem by raising compliance costs for technology firms, start-ups, open-source projects, educational institutions, research organisations, and artificial intelligence developers.

It argued that the proposed amendment might make Nigeria less attractive to technology investors and conflict with the objectives of the Nigeria Startup Act 2022 and the National Digital Economy Policy and Strategy.

Advertisement

“The National Assembly should not achieve indirectly through regulatory localisation requirements what it cannot constitutionally achieve directly through restrictions on social media. The practical consequences for millions of Nigerians would be indistinguishable from a platform ban,” SERAP stated.

It urged Akpabio and Abbas to reject and withdraw the bill, warning that its enactment would breach the Nigerian Constitution and Nigeria’s commitments under international and regional human rights instruments.

“The National Assembly should seize this opportunity to demonstrate its commitment to constitutional democracy, the rule of law, and Nigeria’s digital future by immediately withdrawing the Bill,” SERAP added.

 

Advertisement

Kindly share this post
Continue Reading

Trending