Skip to content

Hanover County schools ransomware attempt

Summary

Hanover County Public Schools logo

Hanover County Public Schools lost divisionwide internet access and multiple systems after a malicious actor accessed network data and attempted to deploy ransomware in March 2026. Instruction continued without normal technology until internet and core platforms began returning March 18. HCPS said personal information may have been viewed or accessed, but it reported no indication of misuse and did not identify the actor.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

Operational impacts

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

Hanover County Public Schools experienced a divisionwide technology disruption after an unknown malicious actor gained access to network data and attempted to deploy ransomware. HCPS said March 12 that cybersecurity professionals were investigating and mitigating a “possible data incident.” Its message referenced an outage notice sent the previous afternoon, placing the earliest documented disruption on March 11.

HCPS confirmed May 4 that the actor tried to deploy ransomware to encrypt parts of the network and that access was terminated soon after detection. The district did not say encryption succeeded. No named threat actor made a stable public claim, and HCPS identified the intruder only as an unknown malicious actor.

Operational significance

Internet service and multiple HCPS systems were unavailable across the school division. Instruction continued without normal technology, students were temporarily asked not to use district Chromebooks as a precaution, and families were directed to contact schools by phone when necessary. HCPS did not report school closures.

The network remained down March 16. On March 18, HCPS said internet service had returned to schools and offices, students could again use Chromebooks at school, and staff were beginning to access PowerSchool, Schoology and other platforms. The district also warned of intermittent impact and said some resources remained inaccessible while restoration continued. March 18 is the latest date on which HCPS documented continuing operational effects.

Data impact

HCPS said personally identifiable information may have been viewed or accessed during the actor’s limited access window. Depending on what an individual had supplied to the district, the information could have included a full name or first initial and last name combined with a Social Security number, financial account information, a driver’s license number or another government-issued identifier.

The district said it had received no indication that personal or student information was misused. It did not identify the exact records reviewed, the number of people involved or whether data was copied or removed, so the supported data-impact classification is unauthorized access rather than confirmed exfiltration.

Disclosure posture

HCPS used qualified cyber- and data-security wording March 12 before our report later that day, supporting OC. The district also directly documented the divisionwide outage, inaccessible systems and offline instruction, supporting OD. The later confirmation of malicious access and an attempted ransomware deployment strengthened the cyber assessment without changing that organization-first sequence.

Current status

The incident is resolved operationally. HCPS restored internet and core instructional technology March 18, and its May notice described the work to restore the network in the past tense. The March 18 notice still documented intermittent impact and inaccessible resources, but no later source established continuing service-delivery effects.

Confidence and uncertainty

Confidence is high in the cyber characterization, operational disruption, unauthorized data access and attempted ransomware deployment because HCPS confirmed each of those elements. Confirmed ransomware confidence refers to the confirmed deployment attempt; it does not establish successful encryption, an extortion demand or payment. Actor confidence remains unresolved.

Analytic gaps

The public record does not establish the access vector, named actor, ransomware family, exact files viewed, successful exfiltration, successful encryption, extortion activity, payment or affected-person count.

Organizations involved

Impacted locations

Sources

Technology Update: March 2026

HCPS’s dated updates show it disclosed a possible data incident March 12; internet and multiple systems remained unavailable through March 16. Internet returned March 18, although intermittent impacts and some inaccessible resources remained during restoration.

Data Incident Information - May 2026

HCPS said an unknown malicious actor accessed network data and attempted to deploy ransomware before its access was terminated. PII may have been viewed or accessed, but the district reported no indication of misuse.

See something that needs correction?

Signed-in members can report an error, update, or missing source.