Skip to content

Denmark School District weeklong internet outage after cyber incident

Summary

Denmark School District logo

Denmark School District lost internet across its facilities for five school days beginning January 30, requiring paper-based instruction and administrative workarounds. The district later acknowledged a potential data security incident; teachers said at least 60 current and former employees were affected and alleged that the district received a ransom note, while INC Ransom separately claimed encryption and theft of about 71 GB. The district did not corroborate the actor’s claims or link reported employee tax fraud to the incident, and the documented internet disruption ended February 5.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internet access disruption

    The organization lost or materially restricted internet connectivity.

  • Educational operations disrupted

    Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Encryption-based extortion

    The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

Incident narrative

Analyst assessment

We reported that Denmark School District lost internet access across its facilities for five school days beginning Jan. 30, forcing teachers, students and staff to use paper-based workarounds. The district later told WBAY that a potential data security incident affected district systems and that it engaged external cybersecurity professionals.

INC Ransom listed denmark.k12.wi.us March 1 and alleged encryption and acquisition of 70.76 GB. The district did not confirm INC Ransom’s responsibility, encryption or data theft. The claim is consistent with a confirmed victim cyber incident but remains an allegation rather than authenticated attribution.

Operational significance

Internet access was unavailable across district facilities for five school days, interrupting connected learning and administrative work. WiscNet’s status record shows the district handoff port down from 7:33 a.m. Jan. 30 and passing traffic again Feb. 5. WiscNet labeled the root cause “Internal” without explaining whether that referred only to the customer-side handoff condition or the underlying security event.

The district was fully operational by March 26. The positive Feb. 5 connectivity evidence supports that date as the end of the documented internet disruption; the continuing investigation and later employee concerns do not extend the operational outage.

Disclosure posture

On March 26, the district said it had no evidence that employee W-9 or tax information had been accessed without authorization and that it was still assessing potential effects on students, employees and the broader community. Four days later, The Denmark News reported that district employees were experiencing tax fraud and that some suspected a connection to the January incident.

At an April 13 school board meeting, teachers said at least 60 current and former employees were affected and criticized the district’s transparency. WBAY reported that one teacher said she had learned the district allegedly received a ransom note. Those statements materially increase concern about employee-data impact and extortion, but they do not establish that the incident caused the tax fraud, authenticate the note or confirm what data was accessed.

Confidence and uncertainty

Confidence is high that the incident was cyber-related and caused the five-school-day internet outage. Ransomware involvement remains assessed at medium confidence because the INC Ransom claim aligns with a confirmed victim cyber incident and a teacher publicly alleged a ransom note, while the district has not confirmed ransomware, encryption, exfiltration or receipt of the note.

Confidence remains low that INC Ransom was responsible. The district did not corroborate the actor’s claim, and the public record does not connect the alleged ransom note to INC Ransom. Employee-data impact is concerning but unresolved: the staff reports and tax-fraud complaints are not a final forensic determination.

Analytic gaps

The public record does not establish the initial access vector, affected systems beyond the internet disruption, whether the alleged ransom note was authentic, what data may have been accessed, whether the reported tax fraud was causally connected, whether the actor published samples, any demand amount or payment, or the district’s final investigative findings.

Threat actor and claim

Listed as: denmark.k12.wi.usSource: otherPublished:

Claim details

INC Ransom listed the district domain and alleged encryption and acquisition of 70.76 GB. The district did not corroborate the actor, encryption or data-theft allegations.

Organizations involved

Impacted locations

Sources

Wisconsin district lost internet for five days after cyber incident

Denmark School District lost internet for five school days, used paper workarounds and later appeared on the INC Ransom leak site.

Denmark School District - Handoff Port Down | 2198187

WiscNet recorded the Denmark School District handoff port down beginning at 7:33 a.m. Jan. 30. The provider saw the network and handoff ports up and passing traffic Feb. 5, later listed a seven-day duration and labeled the root cause ‘Internal’ without further explanation.

INC Ransom lists denmark.k12.wi.us

The threat-intelligence record identifies denmark.k12.wi.us as an INC Ransom victim listing published March 1.

Wisconsin K-12 district hit by weeklong outage

INC Ransom claimed it encrypted the district and acquired 70.76 GB; the district did not corroborate the allegation.

Denmark School District investigating potential data security incident

The district said a potential data security incident affected systems in February, external cyber professionals were engaged and schools were fully operational.

DSD staff experiencing issues with personal data

The Denmark News reported that district employees were experiencing tax fraud and that some believed the issue stemmed from the January cyber incident. The report established employee concerns but not a causal connection to the incident.

Denmark School District staff raise concerns over data breach response

Teachers told the school board that at least 60 current and former employees were affected and criticized the district’s transparency. A teacher said she learned the district allegedly received a ransom note; the district did not publicly authenticate that allegation in the report.

Denmark School District official website

The organization’s official website describes its identity, services, operating role and public or customer-facing programs.

Gazetteer Files

The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.

See something that needs correction?

Signed-in members can report an error, update, or missing source.