Skip to content

Minersville Area School District ransomware attack

Summary

Minersville Area School District logo

Minersville Area School District detected malware installation attempts Dec. 15, 2025, shut down its network and canceled classes Dec. 16-19 while specialists investigated. District officials described ransomware; a Dec. 19 notice said some files were copied without permission and systems had been securely restored.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

Operational impacts

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Minersville Area School District experienced a ransomware incident with material educational disruption. Our Dec. 16 report described the initial network shutdown and school closure. The district superintendent later told Coal Region Canary that ransomware affected school systems and that students would remain out Friday. The district’s Dec. 19 notice confirmed unauthorized copying of some network files and secure restoration.

Operational significance

District computers and network systems were taken offline, and regular classes were canceled from Dec. 16 through at least Dec. 19 across three schools. Some out-of-district student transportation and after-school activities continued. The closure disrupted instruction for the district’s students.

Current status

The Dec. 19 district notice says systems were securely restored, while the file review remained ongoing. The operational interruption is recorded as resolved; this does not imply the investigation or notifications were complete.

Confidence and uncertainty

The district’s own notice confirms the cyber event and copied files. The superintendent’s direct account supports ransomware classification. The copied files were primarily curriculum materials, with some excused-absence notes that could include general health references; the district had not completed its content review as of Dec. 19.

Analytic gaps

Initial access, actor identity, full copied-file scope and final notification outcome remain unresolved.

Organizations involved

Impacted locations

Sources

Ransomware closes Minersville Area schools in Pennsylvania

We reported that Minersville Area School District shut down its network after detected malware and canceled classes Dec. 16 while responding to ransomware.

Minersville Area Forced to Close for Fourth Day After Cyber Attack

Superintendent Michael Maley described ransomware affecting school systems and said students would remain out of class Friday, Dec. 19, pending network clearance.

Notice of Cybersecurity Event

The district says it detected malware installation attempts Dec. 15, took systems offline and securely restored them, and learned some network files were copied without permission.

See something that needs correction?

Signed-in members can report an error, update, or missing source.