Analyst assessment
DysruptionHub’s published report documented that Delano Public Schools’ network was compromised on May 19, 2026, internet access was shut down, and classes were canceled the following day. Subsequent CBS Minnesota reporting said printers across the district produced ransom messages and that school officials characterized the event as ransomware.
The district initially said district data was likely stolen and that it was reviewing what information might have been affected. In a later statement reported by Comparitech, communications director Bobbie Dahlke said the district was confident student and staff data was not compromised because its systems locked the intruders out early, while also saying old file folders were compromised. These statements narrow the potential exposure but do not fully resolve whether other district information was acquired.
Comparitech also reported that the district attributed the intrusion path to a firewall and said LockBit made several threats before demanding $1.2 million. The district said it did not pay because LockBit is sanctioned. LockBit separately claimed responsibility, listed the district and threatened disclosure; DysruptionHub treats the actor identity and theft assertions as claims rather than confirmed attribution or confirmed publication.
Operational significance
The district canceled classes for approximately 2,400 students on May 20 while specialists tested the network and determined whether systems were safe. The closure interrupted in-person education across the district and affected roughly 370 employees. Internet access was disabled to limit further damage.
Students returned to class May 21 using limited wired access while wireless connectivity and other systems remained restricted. On June 10, the district said it was still feeling effects from the incident, extending the latest supported operational-impact observation beyond the initial staged reopening. The public record does not identify which functions remained impaired on that date.
Disclosure posture
The district’s first public notice described a cyber incident and announced the closure without identifying ransomware. Later statements disclosed ransom messages, probable data theft, a firewall-related intrusion path, compromised old file folders, the $1.2 million demand, nonpayment and confidence that student and staff data was not compromised. The evolving statements materially increased public understanding but also leave a source tension over the scope of data acquisition.
Current status
June 10 is the latest date on which reviewed reporting documented continuing operational effects. Fifty-five calendar days had elapsed by August 4 without a newer operational observation, so the incident remains presumed resolved. The district has not published a final restoration notice or technical all-clear that would support resolved status.
Confidence and uncertainty
Confidence is high that ransomware occurred because the district described network compromise, ransom messages, threats and a $1.2 million demand. Confidence is high that the incident disrupted educational operations because classes were canceled and network access remained restricted during the return to school.
Confidence is medium that some data was acquired. The district initially said theft was likely and later said old file folders were compromised, while expressing confidence that student and staff data was not compromised. LockBit’s theft and disclosure claims add threat-actor evidence but do not independently establish what data was taken or whether it was published.
Analytic gaps
The reviewed sources do not identify the firewall product, exploited vulnerability, compromised account or device, ransomware variant, encryption scope, dwell time, backup impact, payment instructions or complete recovery date. They also do not identify confirmed stolen-data categories, affected-person counts, whether notifications were required, whether LockBit published data, or whether the LockBit claimant directly conducted the intrusion.