Krum Public Library ransomware disrupted Wi-Fi
Summary
Krum Public Library confirmed that a May 14, 2026, ransomware attack disrupted computer access, printing and Wi-Fi and temporarily limited checkout to five items. The library later secured its network, and current official pages again advertise normal services; unauthorized file access was confirmed, while NightSpire’s claim to have stolen 50 GB remains unverified.
Key facts
Timeline
-
Incident start:
?
Earliest known or assessed start of malicious activity or incident activity. -
First public signal:
?
Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity. -
First public cyber evidence:
?
Earliest credible public information connecting the incident or disruption to malicious cyber activity. -
Official cyber disclosure:
?
First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related. -
Last impact seen:
?
Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
Primary victim organization
Impacted locations
Organization types
Critical infrastructure sector
DysruptionHub coverage
Incident characteristics
Assessments
DD-CIT classification
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Attack mechanisms
-
Ransomware
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Data impacts
-
Unauthorized data access
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Operational impacts
-
Partial service outage
A service, system, platform, or operational capability remained available only in part or with significant limitations.
-
Network outage
Internal or external network connectivity was unavailable or materially impaired.
-
Customer or public access restricted
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
-
Internet access disruption
The organization lost or materially restricted internet connectivity.
Extortion indicators
-
Ransom demand
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
-
Leak-site listing
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
-
Data-theft extortion
The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.
-
Public leak threat
The actor explicitly threatened to publish or publicly release victim data or incident details.
-
Payment denied
An authoritative source stated that no ransom or extortion payment was made.
Incident narrative
Analyst assessment
DysruptionHub assesses with high confidence that Krum Public Library experienced a ransomware incident beginning May 14, 2026. The library’s public notification said it detected unusual network activity that day and later confirmed a sophisticated ransomware attack. DysruptionHub’s published report documented the library’s May 15 notice that computer access, printing and Wi-Fi were temporarily unavailable and checkout was limited to five items.
The library’s official FAQ said the attackers demanded an extortion payment and that the library decided its resources were better spent preventing another incident. It warned that the decision could lead the attackers to publish data they claimed to have stolen. The public record does not identify the amount demanded or communication channel, and the library did not report making a payment.
Operational significance
The incident caused a material partial outage of public library technology services. Patrons could not use public computers, printing or Wi-Fi, and circulation was restricted through a reduced checkout limit. The library remained open, and the city said the attack did not affect its broader network or other municipal operations or services.
The library said backup technology and assistance from the city’s IT team and managed services provider prevented permanent loss of critical data. It also said the library network had been secured and no further unauthorized access had occurred.
Disclosure posture
The library disclosed unusual network activity on May 14 and documented service effects on May 15. On June 4, the city confirmed ransomware, said federal law enforcement had been notified and published an FAQ describing the payment demand, file review and response. A later NightSpire leak-site listing was not part of the library’s attribution and remains an external actor claim.
Current status
The last dated impact observation remains May 15. By July 26, the library’s current services page again advertised public computers, Wi-Fi and printing as available, while its existing about page listed the normal 10-item checkout limit rather than the temporary five-item restriction. Together with the library’s statement that the network had been secured, this supports a resolved assessment, although the exact restoration date for each service was not published.
Confidence and uncertainty
Confidence is high that ransomware caused the incident and that it disrupted library services because the library confirmed both. The forensic investigation also confirmed that a limited number of files were accessed without authorization. The public record does not establish that specific data was encrypted, copied, removed or published, so the confirmed data impact is unauthorized access rather than confirmed encryption or exfiltration.
Confidence that NightSpire was responsible is low. The group listed Krum Public Library and claimed to be selling 50 GB of financial documents, HR data and supervisor information, but neither the library nor an independent technical source confirmed the actor or authenticated the claimed data.
Analytic gaps
The reviewed sources do not identify the initial access vector, compromised account, affected hosts, vulnerability, ransomware variant, dwell time, encrypted systems or files, ransom amount, demand channel or exact restoration date. They also do not provide a completed file-review result, affected-person count or confirmation that NightSpire possessed or published authentic library data.
Threat actor and claim
Claim details
NightSpire listed Krum Public Library on its leak site and claimed it was selling 50 GB of financial documents, HR data and supervisor information. The claim was not independently verified and was not confirmed by the library.

Organizations involved
Krum Public Library

Locations
Organization type
Critical infrastructure
Impacted locations
Sources
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
DysruptionHub reported that a May 14 ransomware attack temporarily disabled computer access, printing and Wi-Fi and limited checkout to five items. The library later said some files were accessed without authorization, while NightSpire’s claim to possess 50 GB of data remained unverified.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
Krum Public Library’s current about page retained its ransomware notification and listed the library’s regular hours and normal checkout policy of up to 10 items, rather than the five-item incident restriction reported May 15.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
The City of Krum said the library’s network had been secured, no further unauthorized access had occurred and a limited number of files were accessed without authorization. Its attached FAQ said attackers demanded payment, threatened dark-web publication of data they claimed to have stolen and that the library decided not to pay.
- Type: Operational Update
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: Medium
The library’s current services page advertised four public desktop computers, patron Wi-Fi and printing and copying services as available. The page did not state an incident restoration date but provided positive current evidence that the services disrupted in May were again offered.