Analyst assessment
DysruptionHub assesses with high confidence that Community College of Beaver County experienced ransomware and a related data breach. We reported that the college locked down technology March 9 after warning of an encryption-based cryptolocker attack. CCBC later said its investigation found unauthorized access from Jan. 16 through March 9 and that an unauthorized party obtained information.
CCBC said the information potentially affected may have included names, Social Security numbers, passport numbers, and financial account information combined with credentials. The college cautioned that the listed categories were present in affected systems and were not necessarily relevant to every individual.
Operational significance
The attack closed the main campus, canceled classes, blocked access to grades, transcripts and financial information, and forced a mass password reset. Instruction returned in phases through online, asynchronous and limited in-person arrangements before all in-person classes resumed.
CCBC operated three instructional sites during the disruption: its main campus in Center Township, the Aviation Sciences Center in Chippewa Township and the Washington County College Center in McMurray. College updates show Air Traffic Control and other specialized programs continued in person during parts of the recovery, while High School Academy and other courses were canceled, moved online or made asynchronous. The evidence supports a collegewide technology and instructional impact, not a finding that every physical site was closed for the same period.
Current status
CCBC’s April 9 update said the college returned to full operational status March 30, with most campus technology restored and operating at or near full capacity. Continuing forensic analysis and the later data-notification process do not establish continuing service disruption after that date.
Confidence and uncertainty
Confidence is high in the ransomware, unauthorized-access, encryption, data-theft and operational-impact findings because CCBC confirmed them directly. A ransom note and encryption support confirmed ransomware; the later notice independently establishes that information was obtained.
Interlock separately claimed responsibility and alleged theft and publication of 780 GB. CCBC did not attribute the incident to Interlock or corroborate that volume or publication claim, so actor confidence remains low.
Analytic gaps
The public record does not establish the initial access vector, exploited vulnerability, precise encryption scope, number of affected people, individual-level data combinations, ransom amount, payment status or final forensic findings. It also does not verify Interlock’s responsibility, the alleged 780 GB collection or whether data presented by the group was authentic and complete.