Onslow County Schools cyberattack disrupted phones
Summary
Onslow County Schools detected unauthorized criminal activity June 9, 2026, disrupting phones, internet, digital services, testing and graduation livestreams across the district. The district later said a relatively small portion of data was exfiltrated; by June 23 the attack was contained and major services were returning, but staged infrastructure restoration and the data-impact review remained underway.
Key facts
Timeline
-
Incident start:
?
Earliest known or assessed start of malicious activity or incident activity. -
First public signal:
?
Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity. -
First public cyber evidence:
?
Earliest credible public information connecting the incident or disruption to malicious cyber activity. -
Official cyber disclosure:
?
First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related. -
Last impact seen:
?
Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
Primary victim organization
Impacted locations
Organization types
Critical infrastructure sector
DysruptionHub coverage
Incident characteristics
Assessments
- Status:
- Presumed Resolved
- Incident confidence:
- High
- Ransomware:
- Unresolved
DD-CIT classification
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Attack mechanisms
-
Unauthorized access
Unauthorized access to systems, accounts, networks, or data.
Data impacts
-
Data theft or exfiltration
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
-
Data unavailable
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Operational impacts
-
Phone service disruption
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
-
Internet access disruption
The organization lost or materially restricted internet connectivity.
-
Educational operations disrupted
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
-
Alternate service channel required
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
-
Complete service outage
A primary service, system, platform, or operational capability became entirely unavailable.
-
Partial service outage
A service, system, platform, or operational capability remained available only in part or with significant limitations.
-
Network outage
Internal or external network connectivity was unavailable or materially impaired.
-
Internal systems unavailable
Internal business, administrative, operational, or staff-facing systems were unavailable.
-
Service delay
Services continued but with longer processing, response, delivery, or completion times.
Extortion indicators
-
Unknown extortion indicators
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
Incident narrative
Analyst assessment
DysruptionHub assesses with high confidence that Onslow County Schools experienced a malicious cyberattack beginning June 9, 2026. The district initially described a districtwide phone and internet outage as a technical issue. In its June 13 cybersecurity notice, it confirmed that technology staff detected a cybersecurity incident affecting the network June 9, secured systems and notified local, state and federal authorities.
The district’s June 23 incident page described the event as a criminal cyberattack by a sophisticated but unnamed threat actor. OCS said affected systems were isolated, the criminal activity was stopped and the multi-agency forensic investigation was completed before the response moved into recovery and restoration.
OCS also said it believed a relatively small portion of its overall data was exfiltrated, meaning copied or taken from the network. Activity traced by the district appeared concentrated in areas not associated with sensitive personal data, but OCS could not rule out access to student or staff personally identifiable information. This establishes data theft or exfiltration but not the data categories, affected population or notification obligations.
Operational significance
The incident disrupted phone and internet services across Onslow County Schools and affected core servers, network systems and digital services used across more than 42 sites. End-of-Course retesting schedules changed, and schools prepared to record and later post graduation ceremonies when livestreaming was unavailable, according to DysruptionHub’s report.
Recovery proceeded in stages. WCTI reported June 19 that a June 17 district update said every school had regained inbound and outbound telephone service, all schools had wireless connectivity restored in key locations, and many critical Finance, Human Resources, Operations and Communications services were back. Credit Recovery was scheduled to begin June 22. The report also said work remained underway to rebuild servers, network systems and digital services.
Disclosure posture
OCS first disclosed the outage June 9 as a technical issue affecting phones and internet. The district first publicly confirmed the cybersecurity incident in its June 13 notice, which said the investigation was focused on whether student or staff personal data had been accessed or taken.
By June 23, the district had confirmed the criminal nature of the event and acknowledged believed exfiltration of a relatively small portion of its data. OCS warned that those claiming responsibility were known for financial extortion tactics, but it did not name the claimant or disclose a demand, payment, leak threat, negotiation or data publication. That wording supports unresolved extortion indicators, not a confirmed ransomware or extortion outcome.
Current status
The June 23 official page said the incident was contained and the forensic investigation had been completed, but it continued to label technology restoration as underway. OCS said infrastructure restoration was in progress, much work remained, full service would return in stages and restoration timelines were still to be determined. This does not support the prior narrative’s assertion that the same page declared the network and phone system fully operational.
No later district all-clear or newer evidence of operational disruption was found through the July 26 cutoff. June 23 is therefore the last supported operational-impact observation. Because 33 days had elapsed without a newer observation, the incident is presumed resolved under DysruptionHub’s operational-status policy. Silence does not establish a definitive resolution date, so occurred_end remains unknown.
Confidence and uncertainty
Confidence is high that malicious cyber activity caused material disruption because OCS confirmed unauthorized criminal activity, containment actions and a multi-agency response, while contemporaneous reporting documented districtwide communications and internet outages and effects on school activities.
Confidence is high that some data was exfiltrated because the district explicitly said it believed a relatively small portion was copied or taken. Confidence is low regarding the data’s sensitivity and affected population because OCS said traced activity appeared outside sensitive-data areas while also stating that student or staff personal information could not be ruled out.
Ransomware confidence remains unresolved. No public source reviewed confirms unauthorized encryption, a ransomware family, ransom note, demand, payment or leak-site listing. The threat actor also remains unresolved: the district referred to a sophisticated actor and to those claiming responsibility but did not provide a name or evidence sufficient for registry attribution.
Analytic gaps
The public record does not identify the initial access vector, exploited vulnerability, malware or tooling, attacker dwell time, persistence mechanisms, exact systems containing exfiltrated data, affected data categories, number of affected people or whether individual notifications will be required.
The record also does not establish the claimant’s identity, the form or recipient of any extortion communication, whether a demand was made, whether stolen data was threatened or published, or whether any payment occurred. A later district notice, forensic report, law-enforcement statement, breach filing or verified actor claim could materially change the assessment.
Organizations involved
Onslow County Schools

Organization type
Critical infrastructure
Impacted locations
Sources
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
DysruptionHub reported that Onslow County Schools confirmed unauthorized criminal activity after initially describing districtwide phone and internet outages as a technical issue. The disruption affected End-of-Course retesting and graduation livestreams, and the district said the incident remained under active investigation.
- Type: Official Statement
- Stance: Confirm
- Platform: Social Platform
- Medium: Web Page
- Confidence: High
Onslow County Schools said it detected unauthorized criminal activity in its technology infrastructure during the early morning of June 9. District staff took protective action and coordinated with local, state and federal law enforcement and cybersecurity authorities.
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
WCTI reported that districtwide phone and internet outages affected End-of-Course retesting and could prevent graduation livestreams. Schools planned direct schedule updates for students and delayed video uploads if livestreaming remained unavailable.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
Onslow County Schools confirmed June 13 that its IT staff detected a cybersecurity incident affecting the network June 9, immediately secured systems and notified local, state and federal authorities. The investigation remained focused on whether student or staff personal data was accessed or taken.
- Type: Operational Update
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
The district’s June 23 page confirmed a criminal cyberattack, containment and completed forensic work; said a relatively small portion of overall data was believed exfiltrated; and could not rule out student or staff PII. Infrastructure restoration remained in progress, much work remained, full service was staged and timelines were undetermined.
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
WCTI reported June 19 that a June 17 district update said all schools had restored inbound and outbound phone service, all schools had Wi-Fi in key locations, and many critical Finance, Human Resources, Operations and Communications services were restored. Infrastructure rebuilding remained underway.