Skip to content

Pell City Schools cyberattack and SafePay claim

Summary

Pell City Schools logo

A local radio station reported a Pell City Schools cyber incident Dec. 14, 2025, as paper-based instruction and phone trouble were reported. The district later documented an internet outage and told families some files were copied but its student information system was unaffected. SafePay listed the district, but its responsibility and the scope of copied data remain unverified.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

External sources identified the event as cyber-related before the organization publicly confirmed it. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Internet access disruption

    The organization lost or materially restricted internet connectivity.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Educational operations disrupted

    Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Payment denied

    An authoritative source stated that no ransom or extortion payment was made.

Incident narrative

Analyst assessment

Pell City Schools experienced a cyber incident that disrupted district technology systems and involved unauthorized copying of files. In a Dec. 14 report, local station 94.1 FM The River described a cyber incident and said Superintendent Justin Burns told it a forensic IT team had been called in. The graphic did not quote Burns using the term. Burns later told families that some district files were copied, according to WBRC’s Jan. 6 account. The district did not identify the copied files publicly.

Timeline and operational effects

The Dec. 14 station update said the school system was using paper-and-pencil instruction because of a major IT event and hoped to restore phones that week. These are reported effects; the district has not published a detailed service-by-service account. On Dec. 15, the district said an internet outage would prevent it from livestreaming the Dec. 16 school board meeting. Its post did not specify the cause of that outage.

By Jan. 6, Burns said some technology systems had been affected and the district was working with cybersecurity partners to restore services, WBRC reported. He said the student information system was not affected, but a third party had copied other files. That distinction does not establish which people or records, if any, were exposed.

Extortion and attribution

SafePay listed the district’s domain on a ransomware-tracking page discovered Dec. 23. Burns said the district would not pay the criminals, according to WBRC. The district has not confirmed SafePay’s responsibility, file encryption, a demand amount or publication of copied data. Its payment refusal and the actor listing support an extortion concern but do not by themselves verify the group’s role.

Disclosure posture

The earliest located public cyber-specific report is the Dec. 14 station post. Although it attributes response details to Burns, it does not directly quote him using cyber-specific language. His later letter to families called the matter a security incident, according to WBRC. The district’s Dec. 15 internet-outage post directly documented disruption. This supports external-first, then organization-confirmed cyber transparency and organization-documented disruption.

Current status and analytic gaps

The incident is presumed resolved because no continuing outage was located after the reported restoration work, but no final all-clear or restoration date was found. The public record does not establish initial access, encryption, copied-file categories, affected-person count, whether student or employee information was among the copied files, a verified actor, ransom terms, recovery cost or the final restoration sequence.

Threat actor and claim

Listed as: pellcityschools.netSource: ransomware.livePublished:

Claim details

SafePay listed Pell City Schools; the district did not confirm attribution.

Organizations involved

Impacted locations

  • Pell City, Alabama

    Pell City contains the district's mapped school sites; this links the affected district to its physical community and does not assert site-specific disruption.

Sources

Pell City Schools cyber incident disrupts systems in Alabama

DysruptionHub reported the district’s cyberattack disclosure, copied files, refusal to pay and SafePay listing.

PCSS IT Event update

The Dec. 14 graphic labels the event a cyber incident and says Superintendent Justin Burns told the station a forensic IT team had been called in. It also reports paper-and-pencil instruction and expected phone restoration; it does not quote Burns using cyber-specific words.

Pell City School System board meeting and internet outage notice

The district said its internet outage would prevent livestreaming the Dec. 16 board meeting and that it was working to resolve the problem. The post did not identify a cyber cause.

pellcityschools.net — SafePay claim

SafePay listed pellcityschools.net as a victim. The district did not confirm attribution.

Security incident impacts IT systems at Pell City Schools

WBRC reported the superintendent’s statement that files were copied, systems were being restored and the district would not pay.

Pell City School System data breached by cyber attack

WBRC reported Superintendent Justin Burns’s letter to families: some district systems were affected, an outside party copied files, the student information system was not affected, the district was restoring services, and it would not pay the criminals.

See something that needs correction?

Signed-in members can report an error, update, or missing source.