In a live incident?
If you are currently experiencing an extortion via AI incident, start following your cyber response plan immediately.
Contact your IT provider for support or reach out to the Risk Protection Agreement (RPA) if you are a member.
If you can’t access your cyber response plan, or you don’t have one, follow these instructions. However, you should adjust them to best fit your school.
Immediate actions
Follow your cyber response plan, if you have one.
Follow your safeguarding procedures for any incidents related to inappropriate material.
Secure the device, mailbox or account the has received the communication.
Do not engage or interact with the perpetrators.
Verify the identity of the subject to those impacted and if the media is AI generated. Assume all media is fake until proven otherwise.
Review all social media and relevant accounts for unauthorised access.
Report to the local police, Report Fraud, and the ICO if personal data has been breached. If content is shared online, consider contacting Report Remove.
If you (or anyone in your school) receive a ransom demand, follow your safeguarding procedures.
Communicate: prepare a holding statement, communications for carers, and responses for media, with help from your legal team.
Keep all evidence and record it. Include:
- URL links
- Usernames
- platform, app, social media or website
- all information communicated, including any images, video and/or audio