Skip to content

Akron schools cyber incident closed all buildings

Summary

Akron Public Schools detected and contained a June 23, 2026, cyber incident that caused a districtwide network outage and closed every district building June 24. Most programs, offices and athletics resumed June 25, but online credit recovery remained canceled through June 26 while external specialists investigated the incident’s nature and scope.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Incident characteristics

Assessments

Incident confidence:
High
Ransomware:
Unresolved

DD-CIT classification

OC-ODOfficial cyberOfficial disruptionAbout the DD-CIT methodology

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Facility closure

    One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.

  • Educational operations disrupted

    Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.

  • Event or activity cancellation

    Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

Akron Public Schools experienced a cyber incident that caused a districtwide network outage and closed every district building June 24, 2026. The district’s official notice canceled summer school, camps, extended-school-year programs, credit recovery, city programs in schools and athletic activities.

The district later said its IT security team detected and contained the incident June 23 and engaged external cybersecurity specialists. The public record does not identify the access vector, affected systems, malware, ransomware, data impact or threat actor.

Operational significance

The outage interrupted instruction, student programs, athletics and district administration. Signal Akron reported that most programs, offices and athletic activities resumed June 25, while office staff used remote work for connectivity and online credit recovery remained canceled through June 26 with make-up days planned.

June 26 is therefore the latest supported operational-impact date. The district’s later July 2 update concerned containment and investigation; it did not establish that services or systems remained operationally impaired on that date.

Current status

No source reviewed documented continuing operational disruption after June 26. Thirty calendar days had elapsed by the July 26 cutoff, so the incident is presumed resolved under the operational lifecycle. The absence of an authoritative full-restoration or incident-closure notice prevents a resolved assessment. Continuing forensic investigation does not advance the operational clock.

Confidence and uncertainty

Confidence is high that cyber activity caused material disruption because the district confirmed the incident and directly documented the districtwide closure. The mechanism remains unknown, and the public record does not establish unauthorized data access, ransomware, encryption, extortion or attribution.

Analytic gaps

The reviewed sources do not identify the initial-access vector, compromised accounts or hosts, affected systems, malware, dwell time, law-enforcement involvement or restoration method. They also do not establish whether data was accessed or removed, when every system returned, or whether credit-recovery make-up work was completed.

Organizations involved

Impacted locations

Sources

Akron schools say cyber incident caused outage, canceled programs
DysruptionHubBy DysruptionHub StaffPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

DysruptionHub documented the June 23 outage notice, June 24 districtwide closure, June 25 partial reopening and July 2 district cyber confirmation. The district detected and contained the June 23 incident but did not disclose affected systems, data impact, ransomware, law-enforcement involvement or full restoration.

All APS buildings closed on June 24, 2026
Akron Public SchoolsPublished: Retrieved:
  • Type: Operational Update
  • Stance: Confirm
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

Akron Public Schools announced that every district building would close June 24 because of a districtwide unanticipated network outage. Summer schools, camps, extended-school-year programs, secondary credit recovery, city programs held in schools and all athletic activities were canceled.

Akron Public Schools shuttered for cybersecurity breach
Signal AkronBy Carissa WoytachPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

Signal Akron reported June 25 that district officials attributed the outage to a cybersecurity breach. APS remained offline June 24; most programs, athletics and offices were to resume June 25, office staff would work remotely for Wi-Fi access, and online credit recovery remained canceled through June 26 with make-up days planned.

Akron Public Schools investigating scope of cyber incident
Akron Beacon JournalBy Kelli WeirPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

The Akron Beacon Journal reported that a July 2 district release said its IT security team detected and contained the June 23 cyber incident and engaged external cybersecurity experts to investigate its nature and scope. The district provided no affected-system or data details.