Analyst assessment
We reported that Alamo Heights ISD lost districtwide internet, Wi-Fi, Gmail and Google application access beginning March 23 while forensic specialists investigated. The district later confirmed ransomware, reported the matter to the FBI and restored systems March 27.
A later forensic review found that personal information was accessed and potentially downloaded. A Texas attorney general filing counted 26,629 affected people and identified names, Social Security numbers, driver’s license numbers, financial information and medical information among the affected data. The district notified affected people by mail, said normal operations had resumed and said it did not pay a ransom.
Operational significance
The outage affected school buildings and offices, restricted digital instruction and administration, and led the district to ask visitors to avoid campuses. Phone and door-security systems remained operational. The district’s March 27 restoration notice supports resolved operational status; the later breach notification does not extend the service-impact period.
The district’s current directory identifies seven facilities across Alamo Heights and San Antonio. The official mailing addresses use San Antonio throughout, but municipal-boundary and OpenStreetMap checks place the Central Office, Alamo Heights High School and Cambridge Elementary School in Alamo Heights; the junior school, Woodridge Elementary School and Howard Early Childhood Center are in San Antonio’s Oak Park neighborhood; and the Educational Development Center/Excel Academy site is in San Antonio near Crownhill Park.
Data impact and extortion
The district’s finding supports unauthorized data access and exposure but does not establish which records were downloaded. WorldLeaks listed “Alamo Heights School District” April 1, and Qilin later listed the same name May 28. Those separate leak-site claims are concrete external cyber evidence, but neither listing authenticates the alleged data or proves that the claimant caused the March outage. Their conflict leaves actor attribution unresolved.
The district said it paid no ransom. Public reporting does not establish a demand amount, negotiation record or payment request from either claimant.
Confidence and uncertainty
Confidence is high that ransomware caused the documented outage and that the district later confirmed unauthorized access to personal information. Actor confidence remains unresolved because the two stable claimant listings conflict and neither is authenticated by the district.
Analytic gaps
The initial access vector, precise encryption scope, confirmed exfiltration scope and responsible actor remain unresolved. The available evidence supports a resolved ransomware incident with a confirmed data breach, not confirmed attribution to WorldLeaks or Qilin.