Skip to content

Krum Public Library ransomware disrupted Wi-Fi

Summary

Krum Public Library confirmed that a May 14, 2026, ransomware attack disrupted computer access, printing and Wi-Fi and temporarily limited checkout to five items. The library later secured its network, and current official pages again advertise normal services; unauthorized file access was confirmed, while NightSpire’s claim to have stolen 50 GB remains unverified.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Incident characteristics

Assessments

Status:
Resolved
Incident confidence:
High
Ransomware:
Confirmed
Attribution:
Low

DD-CIT classification

OC-ODOfficial cyberOfficial disruptionAbout the DD-CIT methodology

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Internet access disruption

    The organization lost or materially restricted internet connectivity.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Payment denied

    An authoritative source stated that no ransom or extortion payment was made.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Krum Public Library experienced a ransomware incident beginning May 14, 2026. The library’s public notification said it detected unusual network activity that day and later confirmed a sophisticated ransomware attack. DysruptionHub’s published report documented the library’s May 15 notice that computer access, printing and Wi-Fi were temporarily unavailable and checkout was limited to five items.

The library’s official FAQ said the attackers demanded an extortion payment and that the library decided its resources were better spent preventing another incident. It warned that the decision could lead the attackers to publish data they claimed to have stolen. The public record does not identify the amount demanded or communication channel, and the library did not report making a payment.

Operational significance

The incident caused a material partial outage of public library technology services. Patrons could not use public computers, printing or Wi-Fi, and circulation was restricted through a reduced checkout limit. The library remained open, and the city said the attack did not affect its broader network or other municipal operations or services.

The library said backup technology and assistance from the city’s IT team and managed services provider prevented permanent loss of critical data. It also said the library network had been secured and no further unauthorized access had occurred.

Disclosure posture

The library disclosed unusual network activity on May 14 and documented service effects on May 15. On June 4, the city confirmed ransomware, said federal law enforcement had been notified and published an FAQ describing the payment demand, file review and response. A later NightSpire leak-site listing was not part of the library’s attribution and remains an external actor claim.

Current status

The last dated impact observation remains May 15. By July 26, the library’s current services page again advertised public computers, Wi-Fi and printing as available, while its existing about page listed the normal 10-item checkout limit rather than the temporary five-item restriction. Together with the library’s statement that the network had been secured, this supports a resolved assessment, although the exact restoration date for each service was not published.

Confidence and uncertainty

Confidence is high that ransomware caused the incident and that it disrupted library services because the library confirmed both. The forensic investigation also confirmed that a limited number of files were accessed without authorization. The public record does not establish that specific data was encrypted, copied, removed or published, so the confirmed data impact is unauthorized access rather than confirmed encryption or exfiltration.

Confidence that NightSpire was responsible is low. The group listed Krum Public Library and claimed to be selling 50 GB of financial documents, HR data and supervisor information, but neither the library nor an independent technical source confirmed the actor or authenticated the claimed data.

Analytic gaps

The reviewed sources do not identify the initial access vector, compromised account, affected hosts, vulnerability, ransomware variant, dwell time, encrypted systems or files, ransom amount, demand channel or exact restoration date. They also do not provide a completed file-review result, affected-person count or confirmation that NightSpire possessed or published authentic library data.

Threat actor and claim

Listed as: Krum Public LibrarySource: otherPublished: Discovered:

Claim details

NightSpire listed Krum Public Library on its leak site and claimed it was selling 50 GB of financial documents, HR data and supervisor information. The claim was not independently verified and was not confirmed by the library.

Screenshot documenting NightSpire claim

Organizations involved

Impacted locations

Sources

Krum, Texas, library ransomware disrupted computers, Wi-Fi
DysruptionHubBy DysruptionHub StaffPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

DysruptionHub reported that a May 14 ransomware attack temporarily disabled computer access, printing and Wi-Fi and limited checkout to five items. The library later said some files were accessed without authorization, while NightSpire’s claim to possess 50 GB of data remained unverified.

Krum Public Library Cybersecurity Event
Krum Public LibraryRetrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

Krum Public Library’s current about page retained its ransomware notification and listed the library’s regular hours and normal checkout policy of up to 10 items, rather than the five-item incident restriction reported May 15.

Important Notification - Krum Public Library Cybersecurity Event
City of Krum / Savvy CitizenPublished: Retrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

The City of Krum said the library’s network had been secured, no further unauthorized access had occurred and a limited number of files were accessed without authorization. Its attached FAQ said attackers demanded payment, threatened dark-web publication of data they claimed to have stolen and that the library decided not to pay.

Library Services
Krum Public LibraryRetrieved:
  • Type: Operational Update
  • Stance: Confirm
  • Platform: Website
  • Medium: Web Page
  • Confidence: Medium

The library’s current services page advertised four public desktop computers, patron Wi-Fi and printing and copying services as available. The page did not state an incident restoration date but provided positive current evidence that the services disrupted in May were again offered.