Claim details
NightSpire listed Krum Public Library on its leak site and claimed it was selling 50 GB of financial documents, HR data and supervisor information. The claim was not independently verified and was not confirmed by the library.

Krum Public Library confirmed that a May 14, 2026, ransomware attack disrupted computer access, printing and Wi-Fi and temporarily limited checkout to five items. The library later secured its network, and current official pages again advertise normal services; unauthorized file access was confirmed, while NightSpire’s claim to have stolen 50 GB remains unverified.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The organization lost or materially restricted internet connectivity.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.
The actor explicitly threatened to publish or publicly release victim data or incident details.
An authoritative source stated that no ransom or extortion payment was made.
DysruptionHub assesses with high confidence that Krum Public Library experienced a ransomware incident beginning May 14, 2026. The library’s public notification said it detected unusual network activity that day and later confirmed a sophisticated ransomware attack. DysruptionHub’s published report documented the library’s May 15 notice that computer access, printing and Wi-Fi were temporarily unavailable and checkout was limited to five items.
The library’s official FAQ said the attackers demanded an extortion payment and that the library decided its resources were better spent preventing another incident. It warned that the decision could lead the attackers to publish data they claimed to have stolen. The public record does not identify the amount demanded or communication channel, and the library did not report making a payment.
The incident caused a material partial outage of public library technology services. Patrons could not use public computers, printing or Wi-Fi, and circulation was restricted through a reduced checkout limit. The library remained open, and the city said the attack did not affect its broader network or other municipal operations or services.
The library said backup technology and assistance from the city’s IT team and managed services provider prevented permanent loss of critical data. It also said the library network had been secured and no further unauthorized access had occurred.
The library disclosed unusual network activity on May 14 and documented service effects on May 15. On June 4, the city confirmed ransomware, said federal law enforcement had been notified and published an FAQ describing the payment demand, file review and response. A later NightSpire leak-site listing was not part of the library’s attribution and remains an external actor claim.
The last dated impact observation remains May 15. By July 26, the library’s current services page again advertised public computers, Wi-Fi and printing as available, while its existing about page listed the normal 10-item checkout limit rather than the temporary five-item restriction. Together with the library’s statement that the network had been secured, this supports a resolved assessment, although the exact restoration date for each service was not published.
Confidence is high that ransomware caused the incident and that it disrupted library services because the library confirmed both. The forensic investigation also confirmed that a limited number of files were accessed without authorization. The public record does not establish that specific data was encrypted, copied, removed or published, so the confirmed data impact is unauthorized access rather than confirmed encryption or exfiltration.
Confidence that NightSpire was responsible is low. The group listed Krum Public Library and claimed to be selling 50 GB of financial documents, HR data and supervisor information, but neither the library nor an independent technical source confirmed the actor or authenticated the claimed data.
The reviewed sources do not identify the initial access vector, compromised account, affected hosts, vulnerability, ransomware variant, dwell time, encrypted systems or files, ransom amount, demand channel or exact restoration date. They also do not provide a completed file-review result, affected-person count or confirmation that NightSpire possessed or published authentic library data.
NightSpire listed Krum Public Library on its leak site and claimed it was selling 50 GB of financial documents, HR data and supervisor information. The claim was not independently verified and was not confirmed by the library.


DysruptionHub reported that a May 14 ransomware attack temporarily disabled computer access, printing and Wi-Fi and limited checkout to five items. The library later said some files were accessed without authorization, while NightSpire’s claim to possess 50 GB of data remained unverified.
Krum Public Library’s current about page retained its ransomware notification and listed the library’s regular hours and normal checkout policy of up to 10 items, rather than the five-item incident restriction reported May 15.
The City of Krum said the library’s network had been secured, no further unauthorized access had occurred and a limited number of files were accessed without authorization. Its attached FAQ said attackers demanded payment, threatened dark-web publication of data they claimed to have stolen and that the library decided not to pay.
The library’s current services page advertised four public desktop computers, patron Wi-Fi and printing and copying services as available. The page did not state an incident restoration date but provided positive current evidence that the services disrupted in May were again offered.
Signed-in members can report an error, update, or missing source.