Claim details
Qilin listed Lake Superior State University after the university disclosed ransomware-related disruption. The university has not confirmed Qilin’s role or data theft.
Lake Superior State University experienced an IT disruption beginning around Nov. 10, 2025. A campuswide message from its chief information officer described ransomware affecting some computers, while online learning and other technology services remained limited.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
A specific application or software platform became unavailable or unusable.
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
Our Nov. 16 report reviewed a campuswide message from Lake Superior State University’s chief information officer describing a ransomware attack affecting some campus computers. The university isolated systems and worked with outside security partners and law enforcement. This supports confirmed cyber involvement and a ransomware assessment, though the publicly available material does not establish the malware family or the extent of encryption.
The disruption affected computers and servers used on campus. Moodle access remained limited as of Nov. 16, and student accounts described laboratory desktops that could not be used. Instructional impact varied by course. A university website notice acknowledged outages, but it did not characterize them as a cyberattack. The article also described a campus credit union kiosk outage attributed to campus internet problems; the available evidence does not establish that this kiosk was separately compromised.
The university was still working to restore files and services at the time of the report. No authoritative statement establishing full restoration was found in the reviewed material. The last documented disruption is months old, so the operational status is presumed resolved rather than formally resolved.
Confidence is high that ransomware disrupted university technology because the chief information officer described it in a campuswide message reviewed by DysruptionHub. A ransomware.live listing records a Qilin claim against the university discovered Nov. 25, 2025. That corroborates the existence of a group claim but does not independently establish Qilin’s responsibility or data theft. Data access, exfiltration, ransom demand, payment, initial access and the full set of affected systems remain unresolved. The university has not publicly confirmed the Qilin attribution in the reviewed material.
Qilin listed Lake Superior State University after the university disclosed ransomware-related disruption. The university has not confirmed Qilin’s role or data theft.

Lake Superior State University in Michigan is managing an IT disruption that began around Nov. 10; an internal email described ransomware affecting some campus computers and servers, and Moodle access remained limited as of Sunday.
Signed-in members can report an error, update, or missing source.