Northwest Iowa Community College network intrusion
Summary
Northwest Iowa Community College experienced a computer network disruption in late November and early December 2025 that canceled on-campus classes and impaired campus technology services. The college later confirmed unauthorized activity and said information may have been accessed or downloaded between November 24 and November 26, 2025. Its July 2026 breach filing identified 16,004 Iowa residents whose names and Social Security numbers were potentially affected.
Key facts
Timeline
-
Incident start:
?
Earliest known or assessed start of malicious activity or incident activity. -
First public signal:
?
Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity. -
First public cyber evidence:
?
Earliest credible public information connecting the incident or disruption to malicious cyber activity. -
Official cyber disclosure:
?
First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related. -
Last impact seen:
?
Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing. -
Incident end:
?
Confirmed or defensibly assessed end of material operational disruption or incident activity.
DysruptionHub coverage
Primary victim organization
Impacted location
Organization types
Critical infrastructure sector
Incident characteristics
Assessments
- Status:
- Presumed Resolved
- Incident confidence:
- Medium
- Ransomware:
- Unresolved
DD-CIT classification
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Attack mechanisms
-
Unauthorized access
Unauthorized access to systems, accounts, networks, or data.
Data impacts
-
Unknown data impact
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Operational impacts
-
Network outage
Internal or external network connectivity was unavailable or materially impaired.
-
Educational operations disrupted
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
-
Event or activity cancellation
Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.
-
Staff unable to work normally
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
-
Email disruption
Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.
-
Online portal unavailable
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
-
Internal systems unavailable
Internal business, administrative, operational, or staff-facing systems were unavailable.
-
Application unavailable
A specific application or software platform became unavailable or unusable.
-
Alternate service channel required
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Extortion indicators
-
No known extortion indicator
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
Incident narrative
Analyst assessment
DysruptionHub assesses with medium confidence that unauthorized cyber activity was associated with the Northwest Iowa Community College network disruption disclosed in late November 2025. DysruptionHub’s published report documents the operational chronology and later breach disclosure. The college’s July 8 filing confirms unauthorized activity in its computer systems between November 24 and November 26, 2025, and says the college discovered the activity on November 26.
The filing does not explicitly state that the unauthorized activity caused every operational failure. The cyber activity and disruption occurred in the same period and involved the college’s computer systems, making a connection well supported, but the public evidence does not conclusively establish the full causal scope.
Operational significance
The college’s network disruption page documents material educational and administrative effects. On-campus classes were canceled for December 2, employees were told not to report to work that day, and online classes continued. Campus facilities, residence halls and dining remained operational.
Technology services returned in stages. By December 8, Wi-Fi, printing and limited email access had returned, while Self-Service remained unavailable. A December 9 Facebook response said most systems were operating normally, but some services were still being restored. On December 11, the college said most services, including Self-Service, had been restored while some systems were still stabilizing.
The disruption affected campus Wi-Fi, email, MyPlace, Canvas, Self-Service and other digital systems. Students were given telephone contacts for immediate questions and Business Office assistance while normal digital access was impaired.
Disclosure posture
The college initially described inaccessible systems as technical issues in a November 29 Facebook post. On December 1 it acknowledged a contained computer network disruption, forensic assistance and federal law-enforcement notification, but did not disclose confirmed unauthorized activity or possible information access until the July 8, 2026 filing.
The filing says the potentially affected record review ended May 29, address validation concluded July 6 and written notice began July 8. It identified 16,004 Iowa residents whose names and Social Security numbers were potentially affected and offered complimentary credit monitoring and identity-protection services.
Current status
December 11 is the latest dated operational observation. The college reported that most services had been restored but said some systems were still stabilizing. Searches through July 26 found no later incident-specific all-clear or evidence of continuing disruption. At 227 days without a newer impact observation, the operational disruption is presumed resolved; that lifecycle assessment does not convert the partial restoration notice into an authoritative full-closure statement.
Confidence and uncertainty
Confidence is high that unauthorized activity occurred and that a materially disruptive network event affected the college during the same period. Confidence is medium that the unauthorized activity caused the full operational disruption because the college has not expressly connected every service failure to the intrusion.
The filing says a limited amount of information may have been accessed or downloaded, not that access or download was confirmed. Data impact therefore remains unresolved. The reviewed evidence does not establish data theft, public exposure, publication or misuse.
No public evidence identifies ransomware, an extortion demand or a threat actor. The use of forensic specialists and federal law enforcement reflects the seriousness of the response but does not independently establish ransomware or attribution.
Analytic gaps
The public record does not establish when systems first became unavailable, the initial access vector, affected hosts or accounts, malware family, persistence mechanism, exact restoration date or whether the Thanksgiving break affected detection of operational disruption. It also does not establish whether any information was actually viewed or downloaded, whether people outside Iowa were affected, or whether additional data categories were involved.
Organizations involved
Northwest Iowa Community College

Locations
Organization type
Critical infrastructure
Impacted location
Sheldon, O'Brien County, Iowa, USA
Sources
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
DysruptionHub reporting documented canceled classes, impaired campus technology services, staged restoration through December 11, and the later breach filing while noting that the college had not expressly confirmed causation.
- Type: Operational Update
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
The college said it detected and contained a computer network disruption, engaged forensic specialists, notified federal law enforcement, canceled on-campus classes for December 2, and restored services in stages through December 11 while some systems continued stabilizing.
- Type: Social Post
- Stance: Confirm
- Platform: Social Platform
- Medium: Web Page
- Confidence: Medium
The college said MyPlace, Canvas, Wi-Fi and other digital systems were inaccessible on campus because of technical issues; a December 9 reply said most systems were operating normally while a few services were still being restored.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Document
- Confidence: High
The filing states that the college discovered unauthorized activity on or around November 26, 2025; information may have been accessed or downloaded between November 24 and November 26; review was completed May 29, 2026; and 16,004 Iowa residents were potentially affected by names and Social Security numbers.
- Type: Public Record
- Stance: Confirm
- Platform: Website
- Medium: Document
- Confidence: High
The official calendar lists November 26, 27 and 28, 2025 as Thanksgiving break, establishing that the unauthorized-activity window overlapped the scheduled holiday period.