Analyst assessment
Lehigh Carbon Community College’s March 5 board minutes say an IT disruption began Feb. 27. The college closed all four sites March 4, shifted in-person and hybrid classes online and canceled meetings and activities. We reported that password resets and system restoration were pending.
By March 9, an LCCC spokeswoman said the college had taken its network offline, retained outside cyber specialists for containment and begun a forensic investigation. A college trustee separately called the event a data breach, though the college’s formal communications did not use that term. This supports a confirmed cyber assessment with an unknown mechanism.
Ransomfeed recorded a Medusa claim naming LCCC and lccc.edu on March 17. BlackFog later reported a $100,000 demand and an allegation of exfiltration. Those are actor claims, not confirmation that Medusa caused the disruption, deployed ransomware or removed data.
Operational significance
The main Schnecksville campus reopened March 10. The Allentown, Tamaqua and Lehigh Valley International Airport sites reopened March 23, but Wi-Fi remained unavailable at the satellite sites and landline phones remained down. Instruction, student services and activities resumed with limitations.
An April 23 College Voice notice described an April 20 migration to Zoom Phone and said physical handsets, advanced routing and training remained in progress. That is the latest dated evidence of an operational effect.
Confidence and uncertainty
Confidence is high that a cyber incident caused material collegewide disruption. Ransomware confidence is medium because the Medusa listing and demand align with the response pattern, but LCCC has not confirmed encryption or ransomware. Attribution to Medusa remains low confidence.
No later material outage notice or formal all-clear was found. Current campus activity and routine IT operations support presumed-resolved status rather than confirmed resolution.
Analytic gaps
The public record does not establish the access vector, exploited vulnerability, compromised credential, malware family, encryption, verified exfiltration, affected data, affected-person count, payment outcome, final restoration date or completed forensic findings.