Claim details
INC Ransom listed the district domain and alleged encryption and acquisition of 70.76 GB. The district did not corroborate the actor, encryption or data-theft allegations.
Denmark School District lost internet across its facilities for five school days beginning January 30, requiring paper-based instruction and administrative workarounds. The district later acknowledged a potential data security incident; teachers said at least 60 current and former employees were affected and alleged that the district received a ransom note, while INC Ransom separately claimed encryption and theft of about 71 GB. The district did not corroborate the actor’s claims or link reported employee tax fraud to the incident, and the documented internet disruption ended February 5.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Internal or external network connectivity was unavailable or materially impaired.
The organization lost or materially restricted internet connectivity.
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.
The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.
We reported that Denmark School District lost internet access across its facilities for five school days beginning Jan. 30, forcing teachers, students and staff to use paper-based workarounds. The district later told WBAY that a potential data security incident affected district systems and that it engaged external cybersecurity professionals.
INC Ransom listed denmark.k12.wi.us March 1 and alleged encryption and acquisition of 70.76 GB. The district did not confirm INC Ransom’s responsibility, encryption or data theft. The claim is consistent with a confirmed victim cyber incident but remains an allegation rather than authenticated attribution.
Internet access was unavailable across district facilities for five school days, interrupting connected learning and administrative work. WiscNet’s status record shows the district handoff port down from 7:33 a.m. Jan. 30 and passing traffic again Feb. 5. WiscNet labeled the root cause “Internal” without explaining whether that referred only to the customer-side handoff condition or the underlying security event.
The district was fully operational by March 26. The positive Feb. 5 connectivity evidence supports that date as the end of the documented internet disruption; the continuing investigation and later employee concerns do not extend the operational outage.
On March 26, the district said it had no evidence that employee W-9 or tax information had been accessed without authorization and that it was still assessing potential effects on students, employees and the broader community. Four days later, The Denmark News reported that district employees were experiencing tax fraud and that some suspected a connection to the January incident.
At an April 13 school board meeting, teachers said at least 60 current and former employees were affected and criticized the district’s transparency. WBAY reported that one teacher said she had learned the district allegedly received a ransom note. Those statements materially increase concern about employee-data impact and extortion, but they do not establish that the incident caused the tax fraud, authenticate the note or confirm what data was accessed.
Confidence is high that the incident was cyber-related and caused the five-school-day internet outage. Ransomware involvement remains assessed at medium confidence because the INC Ransom claim aligns with a confirmed victim cyber incident and a teacher publicly alleged a ransom note, while the district has not confirmed ransomware, encryption, exfiltration or receipt of the note.
Confidence remains low that INC Ransom was responsible. The district did not corroborate the actor’s claim, and the public record does not connect the alleged ransom note to INC Ransom. Employee-data impact is concerning but unresolved: the staff reports and tax-fraud complaints are not a final forensic determination.
The public record does not establish the initial access vector, affected systems beyond the internet disruption, whether the alleged ransom note was authentic, what data may have been accessed, whether the reported tax fraud was causally connected, whether the actor published samples, any demand amount or payment, or the district’s final investigative findings.
INC Ransom listed the district domain and alleged encryption and acquisition of 70.76 GB. The district did not corroborate the actor, encryption or data-theft allegations.

Denmark School District lost internet for five school days, used paper workarounds and later appeared on the INC Ransom leak site.
WiscNet recorded the Denmark School District handoff port down beginning at 7:33 a.m. Jan. 30. The provider saw the network and handoff ports up and passing traffic Feb. 5, later listed a seven-day duration and labeled the root cause ‘Internal’ without further explanation.
The threat-intelligence record identifies denmark.k12.wi.us as an INC Ransom victim listing published March 1.
INC Ransom claimed it encrypted the district and acquired 70.76 GB; the district did not corroborate the allegation.
The district said a potential data security incident affected systems in February, external cyber professionals were engaged and schools were fully operational.
The Denmark News reported that district employees were experiencing tax fraud and that some believed the issue stemmed from the January cyber incident. The report established employee concerns but not a causal connection to the incident.
Teachers told the school board that at least 60 current and former employees were affected and criticized the district’s transparency. A teacher said she learned the district allegedly received a ransom note; the district did not publicly authenticate that allegation in the report.
The organization’s official website describes its identity, services, operating role and public or customer-facing programs.
The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.
Signed-in members can report an error, update, or missing source.