School Payments Cut Off
Anna has worked as a school accountant for nearly three years, watching it shift gradually from paper to digital—checks first sent by post, then a growing web of centralized systems expected to keep running. When the cyberattack hit, it didn’t just take away her ability to log in and do her work for weeks. It erased a year of records entirely.
“I worked at the school for 27 years. When I started, things were simpler, and a new system kept getting added over time. We used to get bank statements by post. Now I turn on the computer, and the first thing I do is pull the bank statements. The rest of the day varies. I enter invoices, record, and process accounts. Without the computer, I cannot do anything anymore.
One day, I turned on the computer as usual, but I couldn’t connect to the network. The notice said the system had been attacked by a hacker, and we should not attempt to log into the system. They were working on a fix, and that they didn’t know when it would be running again. Four sentences altogether.The same message stayed there for weeks.
I didn’t need more information. They display the warning triangles and exclamation points around, and you figure out the rest yourself. From that announcement I understood I couldn’t work. The payments to suppliers and payrolls were disrupted.
The regional office also took care to announce the attack to the suppliers. Their message: we couldn’t process any payments, including the ones that were urgent.
Payments mattered a lot to the school that handled specialised work with a networks of suppliers. But so did the salaries. The payroll system was affected, and salaries had to be typed in by hand at the regional office. Our payroll personnel handed it to them as a package so it could be processed manually. Invoices had to be entered one by one too.
The system halted and we had to wait—proof, plainly, that I couldn’t do anything about it. Every day I came to work and checked whether the system was back. You do what you can, you find other work to fill the time, because you have to do something. You take time off, run your errands, and wait for more information.
We called the regional office to ask if they knew anything, and they didn’t. The whole time, all we heard was that they were working on a fix, that we should wait, and that we’d be informed.
“You work on something you assume is backed up from every side, and then you find out it isn't safe at all. It's far more vulnerable than I ever thought.”
You have deadlines, and when something has to be done fast, you can’t get to it, and that feels uneasy. What piled up was mainly data entry—everything that needed to go into the system. The payment portal was down, and as a public secondary school, we were required to use that system. There was no way around it. I worried about how much work there would be once it started up again. You have to catch up on all of it.
One day they called and told us everything was fine, that we could work again. I worked overtime to keep up.
The system restored gradually. As for accounting, we believed everything was backed up, but some archives never came back. One entire year of records just disappeared. If you had printed copies of that year stored somewhere, fine—otherwise you'd never see them again.
No further information about the attack was ever given to us. We only found out, informally, that an IT administrator was dismissed over the attack—for negligence. In the end they blamed one employee in the region for failing to protect the data. We never learnt the full damage and how many schools were impacted. There were a lot of rumors swirling around the attack, about why it happened.
What surprised me most was how vulnerable it all is. You work on something you assume is backed up from every side, and then you find out it isn’t safe at all. It’s far more vulnerable than I ever thought.”
Anna, Slovakia