Skip to content

Community College of Beaver County ransomware incident

Summary

Community College of Beaver County logo

Ransomware encrypted Community College of Beaver County systems March 9, closing the main campus and disrupting classes, account access and academic and financial records. CCBC later said an unauthorized party accessed its systems from January 16 through March 9 and obtained information that may have included names, Social Security and passport numbers, and financial account information with credentials. The college returned to full operational status March 30; Interlock’s separate claim of responsibility and 780 GB of stolen data remains uncorroborated.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Data encryption

    Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Educational operations disrupted

    Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.

  • Facility closure

    One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.

  • Event or activity cancellation

    Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Encryption-based extortion

    The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Data sample published

    The actor published or shared a sample of allegedly stolen victim data to substantiate the extortion claim.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Community College of Beaver County experienced ransomware and a related data breach. We reported that the college locked down technology March 9 after warning of an encryption-based cryptolocker attack. CCBC later said its investigation found unauthorized access from Jan. 16 through March 9 and that an unauthorized party obtained information.

CCBC said the information potentially affected may have included names, Social Security numbers, passport numbers, and financial account information combined with credentials. The college cautioned that the listed categories were present in affected systems and were not necessarily relevant to every individual.

Operational significance

The attack closed the main campus, canceled classes, blocked access to grades, transcripts and financial information, and forced a mass password reset. Instruction returned in phases through online, asynchronous and limited in-person arrangements before all in-person classes resumed.

CCBC operated three instructional sites during the disruption: its main campus in Center Township, the Aviation Sciences Center in Chippewa Township and the Washington County College Center in McMurray. College updates show Air Traffic Control and other specialized programs continued in person during parts of the recovery, while High School Academy and other courses were canceled, moved online or made asynchronous. The evidence supports a collegewide technology and instructional impact, not a finding that every physical site was closed for the same period.

Current status

CCBC’s April 9 update said the college returned to full operational status March 30, with most campus technology restored and operating at or near full capacity. Continuing forensic analysis and the later data-notification process do not establish continuing service disruption after that date.

Confidence and uncertainty

Confidence is high in the ransomware, unauthorized-access, encryption, data-theft and operational-impact findings because CCBC confirmed them directly. A ransom note and encryption support confirmed ransomware; the later notice independently establishes that information was obtained.

Interlock separately claimed responsibility and alleged theft and publication of 780 GB. CCBC did not attribute the incident to Interlock or corroborate that volume or publication claim, so actor confidence remains low.

Analytic gaps

The public record does not establish the initial access vector, exploited vulnerability, precise encryption scope, number of affected people, individual-level data combinations, ransom amount, payment status or final forensic findings. It also does not verify Interlock’s responsibility, the alleged 780 GB collection or whether data presented by the group was authentic and complete.

Threat actor and claim

Listed as: Community College of Beaver CountySource: ransomware.livePublished:

Claim details

Interlock listed Community College of Beaver County and claimed it stole 780 GB and published records. CCBC later confirmed unauthorized access and that an unauthorized party obtained information, but it did not attribute the incident to Interlock or corroborate the group’s claimed data volume or publication. The claim supports low-confidence attribution, not proof of actor responsibility or the provenance and completeness of material Interlock presented.

Organizations involved

Impacted locations

  • Chippewa Township, Pennsylvania

    Medium Confidence

    CCBC operated the Aviation Sciences Center in Chippewa Township during the incident. Collegewide accounts and High School Academy instruction were disrupted, while some Air Traffic Control instruction continued in person; the public updates do not establish that the facility itself closed for the full recovery period.

  • McMurray, Pennsylvania

    Medium Confidence

    CCBC's Washington County College Center was at 625 E. McMurray Road during the incident. The college's centralized technology and High School Academy instruction were disrupted, but public updates do not establish that this facility was physically closed for the same period as the main campus.

Sources

CCBC cyberattack triggers IT lockdown

CCBC described an encryption-based cryptolocker attack and locked down technology while campus operations were disrupted.

Pennsylvania Bulletin, Vol. 52, No. 44

The Pennsylvania Bulletin identifies the Western Area Career & Technology Center at 688 Western Ave., Canonsburg mailing address, as being in Chartiers Township, Washington County. CCBC identifies that facility as the current home of its Washington County College Center.

Community College of Beaver County Interlock claim

The victim-specific record identifies Community College of Beaver County and Interlock. The record supports preserving the existence and identity of the claim, not treating the claimant’s allegations about responsibility, access, data volume or publication as verified facts.

Cybercriminals say they hacked Community College of Beaver County

Interlock claimed responsibility and alleged theft of 780 GB and publication of records; CCBC did not acknowledge the claim.

Updates

CCBC documented phased recovery after the March 9 encryption incident, including closures, canceled and remote classes, account resets and limited in-person instruction. Its April 9 update said the college returned to full operational status March 30, with most technology operating at or near full capacity.

Notice of Data Incident

CCBC said it discovered suspicious activity involving encryption March 9. Its investigation found unauthorized access from Jan. 16 through March 9 and determined that an unauthorized party obtained information. Potentially affected categories included names, Social Security and passport numbers, and financial account information with credentials; CCBC said the categories were not relevant to every individual.

CCBC's Washington County College Center Moves to New Building

CCBC said its Washington County College Center relocated June 1 from Intermediate Unit 1 in McMurray to the Western Area Career & Technology Center at 688 Western Ave. near Canonsburg. Classes at the new site were scheduled to begin Aug. 24.

Aviation Academy curriculum

CCBC’s 2026 Aviation Academy material identifies in-person instruction at the Aviation Sciences Center, 125 Cessna Drive in Chippewa, and at the Washington County College Center, 625 E. McMurray Road in McMurray. These were two of CCBC’s three instructional sites during the March disruption.

Community College of Beaver County official website

The organization’s official website describes its identity, services, operating role and public or customer-facing programs.

Gazetteer Files

The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.

See something that needs correction?

Signed-in members can report an error, update, or missing source.