Skip to content

Kearney Public Schools cyberattack

Summary

Kearney Public Schools logo

Kearney Public Schools said a cyberattack compromised its network Oct. 10, 2025, disrupting phones, email and other systems while classes continued. Technology systems were functioning by Oct. 13. The superintendent later said a Fortinet investigation verified Interlock had accessed staff finance records and special education files, including sensitive personal information. The district said it received no ransom demand.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

Operational impacts

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

Kearney Public Schools reported a network-compromising cyberattack discovered Oct. 10, 2025. Phones, email and other network-dependent systems were unavailable while the district and outside specialists worked on recovery. Classes continued. The superintendent later said Fortinet’s incident response investigation verified that Interlock accessed sensitive files. This later victim statement supersedes the initial uncertainty about data access, but does not establish encryption or a ransom demand.

Operational significance

District phones, email and other digital tools were offline, requiring families to contact schools in person. Comparitech quoted Superintendent Jason Mundorf saying a camera server and phone/voicemail server were compromised, with possible staff shared-drive impact. The district said Oct. 13 all technology systems were functioning; the original Facebook page could not be rendered, but Comparitech reproduced that statement. The district’s school directory and office listing place its campuses and administration in Kearney. The separate Census district polygon represents the education service area, not a claim that every device or campus was compromised.

Data access and attribution

In the Oct. 17 superintendent statement, the district said Interlock accessed a staff finance folder containing names, addresses, birth dates, Social Security and driver’s license numbers, passports and bank information for current and former staff. Special education files from 2009 onward contained student identifiers, disability information and Medicaid lists. A 2016 student directory file was also accessed. Nebraska Public Media reported the letter. Interlock’s listing alleged a 354 GB theft, but the district did not validate that volume. Mundorf said no ransom request was received; no encryption or payment was verified.

Current status and gaps

The service outage was resolved by the district’s Oct. 13 statement. The full affected-person count, ultimate data disposition, initial access method and any encryption remain unknown. The district attributed file access to Interlock after its investigation; the actor’s claimed data volume remains unverified.

Threat actor and claim

Listed as: Kearney Public SchoolsSource: ransomware.livePublished:

Claim details

Interlock listed the district and claimed 354 GB access. Superintendent later confirmed the group had accessed sensitive files after a Fortinet investigation, but no ransom demand was received and the volume was not validated.

Organizations involved

Impacted locations

Sources

Kearney Public Schools Oct. 13 restoration post

District said all technology systems were fully functional by Oct. 13.

Interlock claim for Kearney Public Schools

Interlock listed the district and claimed access to confidential data.

Kearney Public Schools addresses cyberattack impact

Fortinet investigation confirmed Interlock accessed current and former staff finance files and special education files; no ransom request.

Kearney Public Schools Oct. 17 superintendent letter

Superintendent said Interlock verified access to sensitive staff and special education records; no ransom requested.

Kearney Public Schools district office

District headquarters place anchor.

Kearney Public Schools school directory

School directory identifies the district campuses.

See something that needs correction?

Signed-in members can report an error, update, or missing source.