Evanston Township High School ransomware closure
Summary
Evanston Township High School District 202 confirmed that a June 7, 2026 ransomware attack disrupted campus safety systems, phones, internet, staff accounts and core servers, closing campus June 8–9. Campus reopened June 10, but technology recovery continued into late July with unavailable portals and records, phased service restoration and temporary workarounds.
Key facts
Timeline
-
Incident start:
?
Earliest known or assessed start of malicious activity or incident activity. -
First public signal:
?
Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity. -
First public cyber evidence:
?
Earliest credible public information connecting the incident or disruption to malicious cyber activity. -
Official cyber disclosure:
?
First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related. -
Last impact seen:
?
Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
Primary victim organization
Impacted locations
Organization types
Critical infrastructure sector
DysruptionHub coverage
Incident characteristics
Assessments
DD-CIT classification
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Attack mechanisms
-
Ransomware
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Data impacts
-
Unknown data impact
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
-
Data unavailable
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Operational impacts
-
Network outage
Internal or external network connectivity was unavailable or materially impaired.
-
Internet access disruption
The organization lost or materially restricted internet connectivity.
-
Email disruption
Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.
-
Phone service disruption
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
-
Internal systems unavailable
Internal business, administrative, operational, or staff-facing systems were unavailable.
-
Facility closure
One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.
-
Safety risk or operational hazard
The disruption created or increased a risk to physical safety, public safety, patient safety, industrial safety, or safe operations.
-
Complete service outage
A primary service, system, platform, or operational capability became entirely unavailable.
-
Partial service outage
A service, system, platform, or operational capability remained available only in part or with significant limitations.
-
Degraded service
Services remained available but with reduced performance, reliability, functionality, capacity, or responsiveness.
-
Online portal unavailable
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
-
Application unavailable
A specific application or software platform became unavailable or unusable.
-
Authentication disruption
Users were unable to authenticate, sign in, access accounts, or use identity-dependent services.
-
Records access disruption
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
-
Educational operations disrupted
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
-
Event or activity cancellation
Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.
-
Manual workaround required
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
-
Staff unable to work normally
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
-
Customer or public access restricted
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Extortion indicators
-
Unknown extortion indicators
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
Incident narrative
Analyst assessment
DysruptionHub assesses with high confidence that Evanston Township High School District 202 experienced a ransomware attack beginning June 7, 2026. The district’s rolling incident page confirms that the event disrupted district systems, internet services and computer infrastructure. DysruptionHub’s initial report and CBS News Chicago documented the immediate campus, communications and safety effects.
The district has not identified the access vector, ransomware family, compromised accounts, encryption scope or responsible actor. Ransomware is confirmed by the victim, but the technical and attribution picture remains limited.
Operational significance
The attack disrupted network connectivity, internet, phones, staff email and Google accounts, eSchool, Home Access Center, myETHS, door access, public-address functions and other emergency or operational systems. Because systems required for safe operations were unavailable, ETHS closed campus June 8–9 and canceled summer school, sports camps and other activities. Campus reopened June 10, but that did not mark full technology restoration.
In a July 16 school-year preparation statement, Superintendent Marcus Campbell said core servers had been inaccessible for about a month and that teams were rebuilding critical systems and restoring services. The district expected some tools, processes and timelines to function differently, with services returning in phases and temporary workarounds continuing into the school year.
The July 17 incident-page update said Home Access Center and myETHS were unavailable, full system restoration had no timetable, staff access remained limited and many district devices required review and reimaging before use. It also said the incident had interrupted transcript-data transfer, although the transcript issue was later corrected.
Current status
Recovery remained active at the July 26 cutoff. The district’s current student-parking page says the incident delayed the parking lottery, forced a temporary replacement process and left detailed account information unavailable online during a workflow with a July 26 deadline. This is direct current evidence of continuing records-access limitations and workarounds, supporting active status and a July 26 last-impact observation.
Confidence and uncertainty
Confidence is high that ransomware caused material educational and safety-related disruption because the district directly confirmed the attack type and affected systems. Data availability was affected because core servers, records portals and some information workflows were inaccessible. Whether personal information was accessed, copied or removed remains unresolved; the district said forensic specialists were still examining that question.
CBS reported that the district had not received a money demand at the time of initial reporting. No later demand, payment, leak-site listing, data publication or actor attribution was found, so extortion details and attribution remain unresolved.
Analytic gaps
The public record does not identify the access vector, ransomware family, dwell time, persistence, affected endpoints or servers, encryption scope, backup impact, ransom amount, payment status or responsible actor. It also does not establish whether student, employee or other sensitive information was acquired, the full recovery cost, or when every affected system and workflow will be restored.
Organizations involved
Evanston Township High School District 202

Organization type
Critical infrastructure
Impacted locations
Sources
- Type: Operational Update
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
The rolling district page, last updated July 17, says campus reopened June 10 but system access and recovery remained limited. Home Access Center, myETHS and phones remained unavailable; staff devices required review or reimaging; full restoration had no timetable; and the district was still investigating whether personal information was accessed.
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
DysruptionHub reported that ransomware disrupted district systems, internet services, phones, staff email, Google accounts, eSchool and Home Access Center. The district closed campus and canceled summer programs because critical operational and safety systems were unavailable.
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
CBS News Chicago reported that the district closed campus after ransomware disrupted internet, phones, emergency notification and public-address systems. The district said it had not yet received a money demand and staff scheduled to work were told to stay home or work remotely.
- Type: Operational Update
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
Superintendent Marcus Campbell said the June incident caused widespread disruption and significant technology damage, leaving core servers inaccessible for about a month. Critical systems were being rebuilt, some tools and processes would not function normally for the start of school, and phased restoration and temporary workarounds would continue.
- Type: Operational Update
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
The district said the cybersecurity incident delayed its 2026-27 parking lottery and required a new temporary application and allocation process. Detailed account information remained unavailable online, and students had to re-register through a replacement form during a process with a July 26 deadline.