Skip to content

Onslow County Schools cyberattack disrupted phones

Summary

Onslow County Schools detected unauthorized criminal activity June 9, 2026, disrupting phones, internet, digital services, testing and graduation livestreams across the district. The district later said a relatively small portion of data was exfiltrated; by June 23 the attack was contained and major services were returning, but staged infrastructure restoration and the data-impact review remained underway.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Incident characteristics

Assessments

Incident confidence:
High
Ransomware:
Unresolved

DD-CIT classification

OC-ODOfficial cyberOfficial disruptionAbout the DD-CIT methodology

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internet access disruption

    The organization lost or materially restricted internet connectivity.

  • Educational operations disrupted

    Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Onslow County Schools experienced a malicious cyberattack beginning June 9, 2026. The district initially described a districtwide phone and internet outage as a technical issue. In its June 13 cybersecurity notice, it confirmed that technology staff detected a cybersecurity incident affecting the network June 9, secured systems and notified local, state and federal authorities.

The district’s June 23 incident page described the event as a criminal cyberattack by a sophisticated but unnamed threat actor. OCS said affected systems were isolated, the criminal activity was stopped and the multi-agency forensic investigation was completed before the response moved into recovery and restoration.

OCS also said it believed a relatively small portion of its overall data was exfiltrated, meaning copied or taken from the network. Activity traced by the district appeared concentrated in areas not associated with sensitive personal data, but OCS could not rule out access to student or staff personally identifiable information. This establishes data theft or exfiltration but not the data categories, affected population or notification obligations.

Operational significance

The incident disrupted phone and internet services across Onslow County Schools and affected core servers, network systems and digital services used across more than 42 sites. End-of-Course retesting schedules changed, and schools prepared to record and later post graduation ceremonies when livestreaming was unavailable, according to DysruptionHub’s report.

Recovery proceeded in stages. WCTI reported June 19 that a June 17 district update said every school had regained inbound and outbound telephone service, all schools had wireless connectivity restored in key locations, and many critical Finance, Human Resources, Operations and Communications services were back. Credit Recovery was scheduled to begin June 22. The report also said work remained underway to rebuild servers, network systems and digital services.

Disclosure posture

OCS first disclosed the outage June 9 as a technical issue affecting phones and internet. The district first publicly confirmed the cybersecurity incident in its June 13 notice, which said the investigation was focused on whether student or staff personal data had been accessed or taken.

By June 23, the district had confirmed the criminal nature of the event and acknowledged believed exfiltration of a relatively small portion of its data. OCS warned that those claiming responsibility were known for financial extortion tactics, but it did not name the claimant or disclose a demand, payment, leak threat, negotiation or data publication. That wording supports unresolved extortion indicators, not a confirmed ransomware or extortion outcome.

Current status

The June 23 official page said the incident was contained and the forensic investigation had been completed, but it continued to label technology restoration as underway. OCS said infrastructure restoration was in progress, much work remained, full service would return in stages and restoration timelines were still to be determined. This does not support the prior narrative’s assertion that the same page declared the network and phone system fully operational.

No later district all-clear or newer evidence of operational disruption was found through the July 26 cutoff. June 23 is therefore the last supported operational-impact observation. Because 33 days had elapsed without a newer observation, the incident is presumed resolved under DysruptionHub’s operational-status policy. Silence does not establish a definitive resolution date, so occurred_end remains unknown.

Confidence and uncertainty

Confidence is high that malicious cyber activity caused material disruption because OCS confirmed unauthorized criminal activity, containment actions and a multi-agency response, while contemporaneous reporting documented districtwide communications and internet outages and effects on school activities.

Confidence is high that some data was exfiltrated because the district explicitly said it believed a relatively small portion was copied or taken. Confidence is low regarding the data’s sensitivity and affected population because OCS said traced activity appeared outside sensitive-data areas while also stating that student or staff personal information could not be ruled out.

Ransomware confidence remains unresolved. No public source reviewed confirms unauthorized encryption, a ransomware family, ransom note, demand, payment or leak-site listing. The threat actor also remains unresolved: the district referred to a sophisticated actor and to those claiming responsibility but did not provide a name or evidence sufficient for registry attribution.

Analytic gaps

The public record does not identify the initial access vector, exploited vulnerability, malware or tooling, attacker dwell time, persistence mechanisms, exact systems containing exfiltrated data, affected data categories, number of affected people or whether individual notifications will be required.

The record also does not establish the claimant’s identity, the form or recipient of any extortion communication, whether a demand was made, whether stolen data was threatened or published, or whether any payment occurred. A later district notice, forensic report, law-enforcement statement, breach filing or verified actor claim could materially change the assessment.

Organizations involved

Impacted locations

Sources

Cyberattack disrupts Onslow County Schools phones and internet
DysruptionHubBy DysruptionHub StaffPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

DysruptionHub reported that Onslow County Schools confirmed unauthorized criminal activity after initially describing districtwide phone and internet outages as a technical issue. The disruption affected End-of-Course retesting and graduation livestreams, and the district said the incident remained under active investigation.

Onslow County Schools cybersecurity incident update
Onslow County SchoolsPublished: Retrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Social Platform
  • Medium: Web Page
  • Confidence: High

Onslow County Schools said it detected unauthorized criminal activity in its technology infrastructure during the early morning of June 9. District staff took protective action and coordinated with local, state and federal law enforcement and cybersecurity authorities.

Technical issues impact internet, phone service across Onslow County Schools
WCTIBy News 12 StaffPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

WCTI reported that districtwide phone and internet outages affected End-of-Course retesting and could prevent graduation livestreams. Schools planned direct schedule updates for students and delayed video uploads if livestreaming remained unavailable.

Important Notice from Onslow County Schools Regarding a Cybersecurity Incident
Onslow County SchoolsBy Brent AndersonPublished: Retrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

Onslow County Schools confirmed June 13 that its IT staff detected a cybersecurity incident affecting the network June 9, immediately secured systems and notified local, state and federal authorities. The investigation remained focused on whether student or staff personal data was accessed or taken.

Archive platform: Archive IsArchived: View archived copy
Technology Services Update:Cybersecurity Incident
Onslow County SchoolsPublished: Retrieved:
  • Type: Operational Update
  • Stance: Confirm
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

The district’s June 23 page confirmed a criminal cyberattack, containment and completed forensic work; said a relatively small portion of overall data was believed exfiltrated; and could not rule out student or staff PII. Infrastructure restoration remained in progress, much work remained, full service was staged and timelines were undetermined.

Archive platform: Archive IsArchived: View archived copy
Onslow County Schools restores phone service and key Wi-Fi after criminal cyberattack
WCTIBy News 12 StaffPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

WCTI reported June 19 that a June 17 district update said all schools had restored inbound and outbound phone service, all schools had Wi-Fi in key locations, and many critical Finance, Human Resources, Operations and Communications services were restored. Infrastructure rebuilding remained underway.