Skip to content

Delano Public Schools ransomware cancels classes

Summary

Delano Public Schools logo

Delano Public Schools canceled classes May 20 after ransomware compromised its network; students returned the next day with limited connectivity. On June 10, the district said effects continued, old file folders were compromised through a firewall, and student and staff data was not compromised, narrowing an earlier statement that district data was likely stolen. LockBit claimed the attack and demanded $1.2 million, which the district said it did not pay.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data encryption

    Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.

Operational impacts

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Educational operations disrupted

    Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.

  • Event or activity cancellation

    Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Encryption-based extortion

    The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Countdown or payment deadline

    The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Direct victim contact

    The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.

  • Payment denied

    An authoritative source stated that no ransom or extortion payment was made.

Incident narrative

Analyst assessment

DysruptionHub’s published report documented that Delano Public Schools’ network was compromised on May 19, 2026, internet access was shut down, and classes were canceled the following day. Subsequent CBS Minnesota reporting said printers across the district produced ransom messages and that school officials characterized the event as ransomware.

The district initially said district data was likely stolen and that it was reviewing what information might have been affected. In a later statement reported by Comparitech, communications director Bobbie Dahlke said the district was confident student and staff data was not compromised because its systems locked the intruders out early, while also saying old file folders were compromised. These statements narrow the potential exposure but do not fully resolve whether other district information was acquired.

Comparitech also reported that the district attributed the intrusion path to a firewall and said LockBit made several threats before demanding $1.2 million. The district said it did not pay because LockBit is sanctioned. LockBit separately claimed responsibility, listed the district and threatened disclosure; DysruptionHub treats the actor identity and theft assertions as claims rather than confirmed attribution or confirmed publication.

Operational significance

The district canceled classes for approximately 2,400 students on May 20 while specialists tested the network and determined whether systems were safe. The closure interrupted in-person education across the district and affected roughly 370 employees. Internet access was disabled to limit further damage.

Students returned to class May 21 using limited wired access while wireless connectivity and other systems remained restricted. On June 10, the district said it was still feeling effects from the incident, extending the latest supported operational-impact observation beyond the initial staged reopening. The public record does not identify which functions remained impaired on that date.

Disclosure posture

The district’s first public notice described a cyber incident and announced the closure without identifying ransomware. Later statements disclosed ransom messages, probable data theft, a firewall-related intrusion path, compromised old file folders, the $1.2 million demand, nonpayment and confidence that student and staff data was not compromised. The evolving statements materially increased public understanding but also leave a source tension over the scope of data acquisition.

Current status

June 10 is the latest date on which reviewed reporting documented continuing operational effects. Fifty-five calendar days had elapsed by August 4 without a newer operational observation, so the incident remains presumed resolved. The district has not published a final restoration notice or technical all-clear that would support resolved status.

Confidence and uncertainty

Confidence is high that ransomware occurred because the district described network compromise, ransom messages, threats and a $1.2 million demand. Confidence is high that the incident disrupted educational operations because classes were canceled and network access remained restricted during the return to school.

Confidence is medium that some data was acquired. The district initially said theft was likely and later said old file folders were compromised, while expressing confidence that student and staff data was not compromised. LockBit’s theft and disclosure claims add threat-actor evidence but do not independently establish what data was taken or whether it was published.

Analytic gaps

The reviewed sources do not identify the firewall product, exploited vulnerability, compromised account or device, ransomware variant, encryption scope, dwell time, backup impact, payment instructions or complete recovery date. They also do not identify confirmed stolen-data categories, affected-person counts, whether notifications were required, whether LockBit published data, or whether the LockBit claimant directly conducted the intrusion.

Threat actor and claim

Listed as: Delano Public SchoolsSource: otherPublished:

Claim details

LockBit claimed responsibility and threatened to release allegedly stolen data if the district did not negotiate.

Organizations involved

Impacted locations

Sources

Delano, Minnesota, schools closed after cyber incident

Delano Public Schools canceled May 20 classes after the district network was compromised and internet access was shut down while experts tested systems. The initial report said the closure affected about 2,400 students and 370 staff members.

Delano becomes latest Minnesota school district hit by ransomware attack

CBS Minnesota reported that printers throughout the district produced ransom messages after unauthorized access was detected May 19. The district characterized the event as ransomware and later said district data was likely stolen.

Cyber incident prompts Delano schools to close Wednesday

KSTP reported that Delano Public Schools canceled classes on May 20 after a cybersecurity incident and announced that students would return in person the following day.

Cybercriminals give Delano Public Schools two weeks to pay ransom

Comparitech reported that LockBit claimed the attack, listed Delano and threatened disclosure. A district spokesperson said effects continued on June 10, attributed the intrusion to a firewall, said old file folders were compromised, expressed confidence that student and staff data was not compromised, disclosed a $1.2 million demand and said the district did not pay.

See something that needs correction?

Signed-in members can report an error, update, or missing source.