Skip to content

Lake Superior State University Ransomware Incident

Summary

Lake Superior State University logo

Lake Superior State University experienced an IT disruption beginning around Nov. 10, 2025. A campuswide message from its chief information officer described ransomware affecting some computers, while online learning and other technology services remained limited.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted location

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Educational operations disrupted

    Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

Our Nov. 16 report reviewed a campuswide message from Lake Superior State University’s chief information officer describing a ransomware attack affecting some campus computers. The university isolated systems and worked with outside security partners and law enforcement. This supports confirmed cyber involvement and a ransomware assessment, though the publicly available material does not establish the malware family or the extent of encryption.

Operational significance

The disruption affected computers and servers used on campus. Moodle access remained limited as of Nov. 16, and student accounts described laboratory desktops that could not be used. Instructional impact varied by course. A university website notice acknowledged outages, but it did not characterize them as a cyberattack. The article also described a campus credit union kiosk outage attributed to campus internet problems; the available evidence does not establish that this kiosk was separately compromised.

Current status

The university was still working to restore files and services at the time of the report. No authoritative statement establishing full restoration was found in the reviewed material. The last documented disruption is months old, so the operational status is presumed resolved rather than formally resolved.

Confidence and uncertainty

Confidence is high that ransomware disrupted university technology because the chief information officer described it in a campuswide message reviewed by DysruptionHub. A ransomware.live listing records a Qilin claim against the university discovered Nov. 25, 2025. That corroborates the existence of a group claim but does not independently establish Qilin’s responsibility or data theft. Data access, exfiltration, ransom demand, payment, initial access and the full set of affected systems remain unresolved. The university has not publicly confirmed the Qilin attribution in the reviewed material.

Threat actor and claim

Listed as: Lake Superior State UniversitySource: ransomware.liveDiscovered:

Claim details

Qilin listed Lake Superior State University after the university disclosed ransomware-related disruption. The university has not confirmed Qilin’s role or data theft.

Organizations involved

Impacted location

Sources

Ransomware disrupts Lake Superior State University in Michigan

Lake Superior State University in Michigan is managing an IT disruption that began around Nov. 10; an internal email described ransomware affecting some campus computers and servers, and Moodle access remained limited as of Sunday.

See something that needs correction?

Signed-in members can report an error, update, or missing source.