Hanover County Public Schools

Hanover County Public Schools lost divisionwide internet access and multiple systems after a malicious actor accessed network data and attempted to deploy ransomware in March 2026. Instruction continued without normal technology until internet and core platforms began returning March 18. HCPS said personal information may have been viewed or accessed, but it reported no indication of misuse and did not identify the actor.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Unauthorized access to systems, accounts, networks, or data.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Internal or external network connectivity was unavailable or materially impaired.
The organization lost or materially restricted internet connectivity.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
Hanover County Public Schools experienced a divisionwide technology disruption after an unknown malicious actor gained access to network data and attempted to deploy ransomware. HCPS said March 12 that cybersecurity professionals were investigating and mitigating a “possible data incident.” Its message referenced an outage notice sent the previous afternoon, placing the earliest documented disruption on March 11.
HCPS confirmed May 4 that the actor tried to deploy ransomware to encrypt parts of the network and that access was terminated soon after detection. The district did not say encryption succeeded. No named threat actor made a stable public claim, and HCPS identified the intruder only as an unknown malicious actor.
Internet service and multiple HCPS systems were unavailable across the school division. Instruction continued without normal technology, students were temporarily asked not to use district Chromebooks as a precaution, and families were directed to contact schools by phone when necessary. HCPS did not report school closures.
The network remained down March 16. On March 18, HCPS said internet service had returned to schools and offices, students could again use Chromebooks at school, and staff were beginning to access PowerSchool, Schoology and other platforms. The district also warned of intermittent impact and said some resources remained inaccessible while restoration continued. March 18 is the latest date on which HCPS documented continuing operational effects.
HCPS said personally identifiable information may have been viewed or accessed during the actor’s limited access window. Depending on what an individual had supplied to the district, the information could have included a full name or first initial and last name combined with a Social Security number, financial account information, a driver’s license number or another government-issued identifier.
The district said it had received no indication that personal or student information was misused. It did not identify the exact records reviewed, the number of people involved or whether data was copied or removed, so the supported data-impact classification is unauthorized access rather than confirmed exfiltration.
HCPS used qualified cyber- and data-security wording March 12 before our report later that day, supporting OC. The district also directly documented the divisionwide outage, inaccessible systems and offline instruction, supporting OD. The later confirmation of malicious access and an attempted ransomware deployment strengthened the cyber assessment without changing that organization-first sequence.
The incident is resolved operationally. HCPS restored internet and core instructional technology March 18, and its May notice described the work to restore the network in the past tense. The March 18 notice still documented intermittent impact and inaccessible resources, but no later source established continuing service-delivery effects.
Confidence is high in the cyber characterization, operational disruption, unauthorized data access and attempted ransomware deployment because HCPS confirmed each of those elements. Confirmed ransomware confidence refers to the confirmed deployment attempt; it does not establish successful encryption, an extortion demand or payment. Actor confidence remains unresolved.
The public record does not establish the access vector, named actor, ransomware family, exact files viewed, successful exfiltration, successful encryption, extortion activity, payment or affected-person count.

We reported that a possible data incident disrupted divisionwide internet access and multiple HCPS systems, forcing instruction without normal technology while the district worked with cybersecurity professionals.
HCPS’s dated updates show it disclosed a possible data incident March 12; internet and multiple systems remained unavailable through March 16. Internet returned March 18, although intermittent impacts and some inaccessible resources remained during restoration.
HCPS said an unknown malicious actor accessed network data and attempted to deploy ransomware before its access was terminated. PII may have been viewed or accessed, but the district reported no indication of misuse.
Signed-in members can report an error, update, or missing source.