Skip to content

Lehigh Carbon Community College cyber disruption

Summary

Lehigh Carbon Community College logo

A cyber-related IT disruption that LCCC said began February 27 closed all four sites March 4 and moved classes online. Campuses reopened in stages by March 23, but Wi-Fi and telephone effects continued into April. Medusa claimed LCCC on March 17, and a secondary tracker reported a $100,000 demand and alleged exfiltration, but the claim does not establish ransomware deployment, data theft or Medusa responsibility.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Educational operations disrupted

    Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.

  • Facility closure

    One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.

  • Event or activity cancellation

    Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.

  • Internet access disruption

    The organization lost or materially restricted internet connectivity.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

Lehigh Carbon Community College’s March 5 board minutes say an IT disruption began Feb. 27. The college closed all four sites March 4, shifted in-person and hybrid classes online and canceled meetings and activities. We reported that password resets and system restoration were pending.

By March 9, an LCCC spokeswoman said the college had taken its network offline, retained outside cyber specialists for containment and begun a forensic investigation. A college trustee separately called the event a data breach, though the college’s formal communications did not use that term. This supports a confirmed cyber assessment with an unknown mechanism.

Ransomfeed recorded a Medusa claim naming LCCC and lccc.edu on March 17. BlackFog later reported a $100,000 demand and an allegation of exfiltration. Those are actor claims, not confirmation that Medusa caused the disruption, deployed ransomware or removed data.

Operational significance

The main Schnecksville campus reopened March 10. The Allentown, Tamaqua and Lehigh Valley International Airport sites reopened March 23, but Wi-Fi remained unavailable at the satellite sites and landline phones remained down. Instruction, student services and activities resumed with limitations.

An April 23 College Voice notice described an April 20 migration to Zoom Phone and said physical handsets, advanced routing and training remained in progress. That is the latest dated evidence of an operational effect.

Confidence and uncertainty

Confidence is high that a cyber incident caused material collegewide disruption. Ransomware confidence is medium because the Medusa listing and demand align with the response pattern, but LCCC has not confirmed encryption or ransomware. Attribution to Medusa remains low confidence.

No later material outage notice or formal all-clear was found. Current campus activity and routine IT operations support presumed-resolved status rather than confirmed resolution.

Analytic gaps

The public record does not establish the access vector, exploited vulnerability, compromised credential, malware family, encryption, verified exfiltration, affected data, affected-person count, payment outcome, final restoration date or completed forensic findings.

Threat actor and claim

Listed as: Lehigh Carbon Community CollegeSource: otherPublished:

Claim details

Ransomfeed recorded a Medusa listing naming Lehigh Carbon Community College and lccc.edu on March 17. BlackFog separately reported a $100,000 demand and an allegation of exfiltration. LCCC has not confirmed Medusa responsibility, ransomware deployment, data removal or payment.

Organizations involved

Impacted locations

Sources

Lehigh Carbon Community College outage points to likely cyber incident

We reported that LCCC closed all four sites beginning March 4, moved in-person and hybrid classes online, canceled activities and prepared password resets while restoring systems. The college had not confirmed ransomware or a breach at publication.

LCCC Board of Trustees meeting minutes

LCCC’s March 5 board minutes say the college was experiencing an IT disruption that began Feb. 27. The minutes also say dual-enrollment registration was extended because of system issues.

LCCC closure continues as cyber specialists investigate IT incident

LCCC spokeswoman Diane Furchner said the college took its network offline, retained outside cyber specialists for containment and began forensic investigation and restoration. All sites remained closed and phone lines were down.

Lehigh Carbon Community College Medusa claim

Ransomfeed’s victim-specific record identifies Lehigh Carbon Community College, lccc.edu and Medusa with a March 17 detection timestamp. It reports no published data and does not display a ransom amount.

Lehigh Carbon CC Still Recovering From Data Breach

The Morning Call reported that all LCCC sites had reopened by March 23, but Wi-Fi remained unavailable at satellite sites and landline phones were still down. A college trustee had called the event a data breach, while formal college communications had not.

College Voice, April 23, 2026

LCCC said it migrated work phone numbers to Zoom Phone on April 20 to restore campus communications. Physical handsets, advanced routing and training remained in progress as a second restoration phase.

The state of ransomware 2026

BlackFog reported that Medusa claimed LCCC, demanded $100,000 and alleged exfiltration. The report does not independently authenticate the claim, verify encryption or establish the amount or contents of any data taken.

Campuses

LCCC’s official directory lists its main Schnecksville campus and additional sites in Allentown, Tamaqua and at Lehigh Valley International Airport.

Gazetteer Files

The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.

Lehigh Carbon Community College official website

The organization’s official website describes its identity, services, operating role and public or customer-facing programs.

See something that needs correction?

Signed-in members can report an error, update, or missing source.