Skip to content

Northwest Iowa Community College network intrusion

Summary

Northwest Iowa Community College experienced a computer network disruption in late November and early December 2025 that canceled on-campus classes and impaired campus technology services. The college later confirmed unauthorized activity and said information may have been accessed or downloaded between November 24 and November 26, 2025. Its July 2026 breach filing identified 16,004 Iowa residents whose names and Social Security numbers were potentially affected.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted location

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

Incident confidence:
Medium
Ransomware:
Unresolved

DD-CIT classification

OC-ODOfficial cyberOfficial disruptionAbout the DD-CIT methodology

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Educational operations disrupted

    Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.

  • Event or activity cancellation

    Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with medium confidence that unauthorized cyber activity was associated with the Northwest Iowa Community College network disruption disclosed in late November 2025. DysruptionHub’s published report documents the operational chronology and later breach disclosure. The college’s July 8 filing confirms unauthorized activity in its computer systems between November 24 and November 26, 2025, and says the college discovered the activity on November 26.

The filing does not explicitly state that the unauthorized activity caused every operational failure. The cyber activity and disruption occurred in the same period and involved the college’s computer systems, making a connection well supported, but the public evidence does not conclusively establish the full causal scope.

Operational significance

The college’s network disruption page documents material educational and administrative effects. On-campus classes were canceled for December 2, employees were told not to report to work that day, and online classes continued. Campus facilities, residence halls and dining remained operational.

Technology services returned in stages. By December 8, Wi-Fi, printing and limited email access had returned, while Self-Service remained unavailable. A December 9 Facebook response said most systems were operating normally, but some services were still being restored. On December 11, the college said most services, including Self-Service, had been restored while some systems were still stabilizing.

The disruption affected campus Wi-Fi, email, MyPlace, Canvas, Self-Service and other digital systems. Students were given telephone contacts for immediate questions and Business Office assistance while normal digital access was impaired.

Disclosure posture

The college initially described inaccessible systems as technical issues in a November 29 Facebook post. On December 1 it acknowledged a contained computer network disruption, forensic assistance and federal law-enforcement notification, but did not disclose confirmed unauthorized activity or possible information access until the July 8, 2026 filing.

The filing says the potentially affected record review ended May 29, address validation concluded July 6 and written notice began July 8. It identified 16,004 Iowa residents whose names and Social Security numbers were potentially affected and offered complimentary credit monitoring and identity-protection services.

Current status

December 11 is the latest dated operational observation. The college reported that most services had been restored but said some systems were still stabilizing. Searches through July 26 found no later incident-specific all-clear or evidence of continuing disruption. At 227 days without a newer impact observation, the operational disruption is presumed resolved; that lifecycle assessment does not convert the partial restoration notice into an authoritative full-closure statement.

Confidence and uncertainty

Confidence is high that unauthorized activity occurred and that a materially disruptive network event affected the college during the same period. Confidence is medium that the unauthorized activity caused the full operational disruption because the college has not expressly connected every service failure to the intrusion.

The filing says a limited amount of information may have been accessed or downloaded, not that access or download was confirmed. Data impact therefore remains unresolved. The reviewed evidence does not establish data theft, public exposure, publication or misuse.

No public evidence identifies ransomware, an extortion demand or a threat actor. The use of forensic specialists and federal law enforcement reflects the seriousness of the response but does not independently establish ransomware or attribution.

Analytic gaps

The public record does not establish when systems first became unavailable, the initial access vector, affected hosts or accounts, malware family, persistence mechanism, exact restoration date or whether the Thanksgiving break affected detection of operational disruption. It also does not establish whether any information was actually viewed or downloaded, whether people outside Iowa were affected, or whether additional data categories were involved.

Organizations involved

Impacted location

Sources

Suspected cyberattack disrupted Northwest Iowa Community College
DysruptionHubBy DysruptionHub StaffPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

DysruptionHub reporting documented canceled classes, impaired campus technology services, staged restoration through December 11, and the later breach filing while noting that the college had not expressly confirmed causation.

Network Disruption
Northwest Iowa Community CollegePublished: Retrieved:
  • Type: Operational Update
  • Stance: Confirm
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

The college said it detected and contained a computer network disruption, engaged forensic specialists, notified federal law enforcement, canceled on-campus classes for December 2, and restored services in stages through December 11 while some systems continued stabilizing.

Northwest Iowa Community College technical issues update
Northwest Iowa Community CollegePublished: Retrieved:
  • Type: Social Post
  • Stance: Confirm
  • Platform: Social Platform
  • Medium: Web Page
  • Confidence: Medium

The college said MyPlace, Canvas, Wi-Fi and other digital systems were inaccessible on campus because of technical issues; a December 9 reply said most systems were operating normally while a few services were still being restored.

Notice of Data Security Event
Northwest Iowa Community CollegeBy Cipriani & Werner, P.C.Published: Retrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Website
  • Medium: Document
  • Confidence: High

The filing states that the college discovered unauthorized activity on or around November 26, 2025; information may have been accessed or downloaded between November 24 and November 26; review was completed May 29, 2026; and 16,004 Iowa residents were potentially affected by names and Social Security numbers.

2025-26 Academic/Work Calendar
Northwest Iowa Community CollegePublished: Retrieved:
  • Type: Public Record
  • Stance: Confirm
  • Platform: Website
  • Medium: Document
  • Confidence: High

The official calendar lists November 26, 27 and 28, 2025 as Thanksgiving break, establishing that the unauthorized-activity window overlapped the scheduled holiday period.