Claim details
SafePay listed Pell City Schools; the district did not confirm attribution.
A local radio station reported a Pell City Schools cyber incident Dec. 14, 2025, as paper-based instruction and phone trouble were reported. The district later documented an internet outage and told families some files were copied but its student information system was unaffected. SafePay listed the district, but its responsibility and the scope of copied data remain unverified.
External sources identified the event as cyber-related before the organization publicly confirmed it. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Unauthorized access to systems, accounts, networks, or data.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
The organization lost or materially restricted internet connectivity.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.
The actor explicitly threatened to publish or publicly release victim data or incident details.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
An authoritative source stated that no ransom or extortion payment was made.
Pell City Schools experienced a cyber incident that disrupted district technology systems and involved unauthorized copying of files. In a Dec. 14 report, local station 94.1 FM The River described a cyber incident and said Superintendent Justin Burns told it a forensic IT team had been called in. The graphic did not quote Burns using the term. Burns later told families that some district files were copied, according to WBRC’s Jan. 6 account. The district did not identify the copied files publicly.
The Dec. 14 station update said the school system was using paper-and-pencil instruction because of a major IT event and hoped to restore phones that week. These are reported effects; the district has not published a detailed service-by-service account. On Dec. 15, the district said an internet outage would prevent it from livestreaming the Dec. 16 school board meeting. Its post did not specify the cause of that outage.
By Jan. 6, Burns said some technology systems had been affected and the district was working with cybersecurity partners to restore services, WBRC reported. He said the student information system was not affected, but a third party had copied other files. That distinction does not establish which people or records, if any, were exposed.
SafePay listed the district’s domain on a ransomware-tracking page discovered Dec. 23. Burns said the district would not pay the criminals, according to WBRC. The district has not confirmed SafePay’s responsibility, file encryption, a demand amount or publication of copied data. Its payment refusal and the actor listing support an extortion concern but do not by themselves verify the group’s role.
The earliest located public cyber-specific report is the Dec. 14 station post. Although it attributes response details to Burns, it does not directly quote him using cyber-specific language. His later letter to families called the matter a security incident, according to WBRC. The district’s Dec. 15 internet-outage post directly documented disruption. This supports external-first, then organization-confirmed cyber transparency and organization-documented disruption.
The incident is presumed resolved because no continuing outage was located after the reported restoration work, but no final all-clear or restoration date was found. The public record does not establish initial access, encryption, copied-file categories, affected-person count, whether student or employee information was among the copied files, a verified actor, ransom terms, recovery cost or the final restoration sequence.
SafePay listed Pell City Schools; the district did not confirm attribution.

Geographic remit of the affected district; not a claim of district-wide physical outage.
Pell City contains the district's mapped school sites; this links the affected district to its physical community and does not assert site-specific disruption.
DysruptionHub reported the district’s cyberattack disclosure, copied files, refusal to pay and SafePay listing.
The Dec. 14 graphic labels the event a cyber incident and says Superintendent Justin Burns told the station a forensic IT team had been called in. It also reports paper-and-pencil instruction and expected phone restoration; it does not quote Burns using cyber-specific words.
The district said its internet outage would prevent livestreaming the Dec. 16 board meeting and that it was working to resolve the problem. The post did not identify a cyber cause.
SafePay listed pellcityschools.net as a victim. The district did not confirm attribution.
WBRC reported the superintendent’s statement that files were copied, systems were being restored and the district would not pay.
WBRC reported Superintendent Justin Burns’s letter to families: some district systems were affected, an outside party copied files, the student information system was not affected, the district was restoring services, and it would not pay the criminals.
Signed-in members can report an error, update, or missing source.