Skip to content

Cyber incident disrupts Cedar Crest College systems

Summary

Cedar Crest College logo

A July 13 cyber incident disrupted Cedar Crest College applications, network drives, OneDrive and file sharing, with July 20 providing the last dated evidence of incomplete restoration. Required orientation and fall classes subsequently began without a located report of continuing material technology disruption, supporting presumed resolution while the exact recovery date remains unknown. The college has not confirmed data access or ransomware, and NightSpire’s claim remains uncorroborated.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted location

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Cloud service disruption

    Cloud-hosted infrastructure, software, storage, identity, or platform services were unavailable or materially impaired.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

Cedar Crest College identified a significant cybersecurity incident at approximately 7:45 a.m. July 13, 2026, affecting portions of its technology environment. The college’s official incident page identified FalconLink, FalconApp, campus network drives, OneDrive and other network- and cloud-based file-sharing systems as affected while it activated emergency response procedures and engaged external specialists.

In its latest dated update July 20, Cedar Crest said it continued to investigate the incident and securely restore system access. The college could not provide a definitive timetable for every affected service and directed users with account, login, device, email, network or application problems to its HelpDesk. DysruptionHub assesses with high confidence that malicious or unauthorized cyber activity caused material disruption to campus technology services.

Operational significance

The incident restricted access to applications and shared-storage services used for academic and administrative work. The July 20 notice is the last positive evidence that restoration remained incomplete. An August 18 retrieval of that unchanged notice did not establish that disruption continued on the retrieval date and therefore does not advance the operational-impact clock.

Current status

The incident is presumed resolved. Cedar Crest published a detailed orientation schedule for required programming and residential move-in August 20-23, and its academic calendar lists August 24 as the beginning of fall classes. No contemporaneous service warning, complaint or report of continuing material technology disruption was located.

Those signals do not prove that every affected system had been restored, and the college did not publish a definitive all-clear or recovery date. They do, however, weigh against presuming that a materially disruptive outage continued through the opening of the academic year. A continuing security investigation or an unchanged incident page does not by itself establish continuing operational impact.

Disclosure posture

Cedar Crest said some information may have been accessed or compromised, but it did not confirm unauthorized access or acquisition. It said affected individuals would be notified if the investigation established that notification was appropriate or required.

Ransomware.live recorded a NightSpire claim associated with Cedar Crest. Our report said the listing identified July 13 as the attack date but provided no description of allegedly stolen data. The college has not attributed the incident to NightSpire or confirmed ransomware involvement.

Confidence and uncertainty

Cyber and disruption confidence remain high because Cedar Crest directly confirmed the incident and named affected systems. Confidence in presumed operational resolution is medium because normal academic activity provides a meaningful counter-signal but no definitive all-clear or restoration date was published. Ransomware and NightSpire attribution confidence remain low.

Analytic gaps

The public record does not establish the initial access vector, intrusion start time, malware family, affected hosts, encryption status, backup impact, information involved, number of affected people or exact restoration date.

Threat actor and claim

Listed as: Cedar Crest CollegeSource: ransomware.livePublished: Discovered:

Claim details

ransomware.live reported that NightSpire claimed Cedar Crest College and identified July 13, 2026, as the attack date. The actor listing did not describe allegedly stolen data and could not be independently verified because the leak site was offline.

Screenshot documenting NightSpire claim

Organizations involved

Impacted location

Sources

Cedar Crest College cyber incident disrupts campus systems in Pennsylvania

Our reporting documented disruption to Cedar Crest College applications and file-sharing systems while investigators examined possible information access. Ransomware.live indexed a NightSpire claim, but we could not independently verify it and the college did not attribute the incident.

Cedar Crest College Cybersecurity Incident

On August 18, Cedar Crest’s live incident page still presented the July 20 notice as its latest update and continued to describe an active investigation, secure restoration without a timetable for every service and support for users experiencing technology-access problems.

Academic Calendar

Cedar Crest’s 2026-27 academic calendar lists August 24, 2026, as the beginning of the 15-week fall semester and accelerated fall session.

August Orientation Schedule 2026

Cedar Crest published a detailed schedule for required first-year orientation, residential move-in and campus programming from August 20 through August 23, immediately before fall classes.

See something that needs correction?

Signed-in members can report an error, update, or missing source.