Skip to content

Cyber incident disrupts Southeastern Oklahoma State University

Summary

Southeastern Oklahoma State University logo

A cyber incident disrupted Southeastern Oklahoma State University systems and closed its Durant campus July 30, July 31 and August 3, 2026, while restoration continued. Ordinary campus operations had resumed by August 18, supporting presumed resolution of the material disruption. Interlock claims it published 710 GB of university data, including records tied to more than 90,000 students, but the university has not confirmed the actor, ransomware or data theft.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted location

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Facility closure

    One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.

  • Educational operations disrupted

    Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Data sample published

    The actor published or shared a sample of allegedly stolen victim data to substantiate the extortion claim.

  • Full data publication

    The actor published or released a substantial or complete set of allegedly stolen victim data.

Incident narrative

Analyst assessment

DysruptionHub assesses that Southeastern Oklahoma State University experienced a confirmed cyber incident affecting its technology environment beginning July 30, 2026. The university’s public notices described a network or service disruption, while KXII reported that university officials characterized the event as an attack by cybercriminals and a cybersecurity incident.

An Interlock claim recorded by ransomware.live names Southeastern Oklahoma State University and se.edu. Screenshots of Interlock’s Worldwide Secrets Blog show the group alleging a 710 GB collection containing 171,499 files and 19,366 folders. Interlock claims the material includes student names, contact details, Social Security numbers, grades, enrollment and financial-aid data, disciplinary and medical information, Forms 1095-C and more than 490 documents. It also claims the collection includes records tied to more than 90,000 students and employee names, birth dates, injury information, Social Security numbers, Medicare cards and child-custody or consent information.

The leak page shows document thumbnails and a “GET” button. A separate screenshot shows a directory listing with 11 folders and their stated sizes, including Data, DataBase, forensic, Shares and Users. The images document what Interlock claimed to possess and presented as available through its site. They do not establish that the files are authentic, originated from the university or were downloadable in full. The university has not confirmed data theft, ransomware or Interlock’s involvement.

Operational significance

The disruption caused three days of closures at the Durant campus. Our report documented the July 30 and 31 closures, and the university’s August 2 update extended the closure through August 3 while system restoration continued.

Canvas and certain online student systems remained available during the disruption, indicating that the closure did not eliminate every educational service. The public record does not identify specific effects on email, identity services, payments, research systems, housing, public safety or satellite locations.

Disclosure posture

The university directly acknowledged the disruption, restoration work, campus closures and continuity of some student-facing services but did not use cyber terminology in the reviewed first-party notices. KXII attributed the cyber characterization to university officials. DysruptionHub treats that as organization-confirmed cyber evidence reported through an independent outlet while preserving the wording difference.

The Interlock claim has no established publication date, so it does not alter the existing organization-first disclosure sequence. The claim adds an external attribution and data-publication allegation but does not establish ransomware or resolve the university’s more cautious public wording.

Current status

The material disruption is presumed resolved. By August 18, the university’s homepage showed fall classes, Welcome Week and ordinary campus events underway, and current student and employee service links were available. No newer source documented continuing campus closure or material service disruption after August 3.

The university has not published an incident-specific technical all-clear or final investigative conclusion. The status reflects the resumption of ordinary operations rather than a finding that every technical recovery task is complete. The later Interlock disclosure claim does not, by itself, indicate continuing service-delivery impact.

Confidence and uncertainty

Confidence is high that a material systems disruption forced three days of campus closures because the university documented those effects directly. Confidence is medium in the public characterization of malicious cyber activity because the victim wording is available through KXII’s attributed reporting, while the stable Interlock claim provides separate but uncorroborated external cyber evidence.

Confidence is medium that Interlock published the listing and displayed alleged samples and a directory interface because direct screenshots show those elements. Ransomware confidence and Interlock attribution confidence remain low. The screenshots do not establish encryption, a ransom demand, exfiltration, authentic data publication or actor responsibility. Data impact remains unknown because no reviewed source independently verifies whether university information was accessed, copied, altered, encrypted, deleted or exposed.

Analytic gaps

The public record does not identify the initial access vector, exploited vulnerability, compromised account or host, malware family, affected-system inventory, dwell time, encryption scope, verified exfiltration scope, ransom demand or payment, third-party role beyond reported incident-response support, restoration method or technical recovery date. It also does not establish when Interlock published its claim, whether the displayed files are authentic or complete, whether the advertised collection was downloadable, or whether the stated volume and record counts are accurate.

Threat actor and claim

Listed as: Southeastern Oklahoma State UniversitySource: ransomware.liveDiscovered:

Claim details

Interlock’s branded leak page names Southeastern Oklahoma State University and se.edu and claims a 710 GB collection containing 171,499 files and 19,366 folders. The group alleges the collection includes student names, contact information, Social Security numbers, grades, enrollment and financial-aid data, disciplinary and medical information, Forms 1095-C, more than 490 documents, records tied to more than 90,000 students, and employee identity, injury, Medicare and child-custody or consent information. The page shows document thumbnails and a “GET” button. A separate screenshot shows a directory listing with 11 folders and their stated sizes. The images document what Interlock claimed to possess and presented as available through its site. They do not establish that the files are authentic, originated from the university or were downloadable in full. The university has not confirmed data theft, ransomware or Interlock’s involvement.

Screenshot documenting Interlock claim

Organizations involved

Impacted location

Sources

Suspected cyber incident closes Southeastern Oklahoma State campus for two days

Southeastern Oklahoma State University closed its Durant campus for two days and temporarily took some computer systems offline after reporting a network disruption affecting campus systems. The university’s public notices described the incident only as a network disruption; KXII was the only reviewed source attributing it to cybercriminals. No ransomware, data theft, ransom demand, law-enforcement involvement, or responsibility claim was publicly confirmed.

University network disruption and July 30 closure notice

The university said it identified a network disruption affecting campus systems and closed the campus for the remainder of July 30 while its information-technology team worked to restore normal operations.

University network disruption and July 31 closure update

In an evening update, the university said the network disruption affected some campus systems and announced that the campus would remain closed Friday, July 31, while IT staff continued restoration work.

Southeastern attacked by cyber criminals, university investigating incident

KXII reported that Southeastern Oklahoma State University said it was attacked by cyber criminals on Thursday. The report said the cybersecurity incident forced the university to take some computer systems offline, that third-party experts were assisting the investigation, and that officials were still determining the nature and scope of the attack.

University service-disruption and August 3 closure update

The university said restoration of university systems remained ongoing following a service disruption, announced that campus would be closed Monday, August 3, and stated that Canvas and online student systems remained operational. It reported steady progress and said it was optimistic normal campus operations would resume soon.

Southeastern Oklahoma State University to reopen Tuesday after cybersecurity incident

KXII reported that Southeastern Oklahoma State University’s campus was expected to reopen Tuesday after what the outlet called a cybersecurity incident. The page synopsis said online courses continued during the investigation and campus was expected to reopen.

Home | Southeastern Oklahoma State University

On August 18, the university homepage showed fall classes, Welcome Week and ordinary campus events underway. Current student and employee service links were available, and no continuing incident closure or outage notice was displayed.

Southeastern Oklahoma State University Interlock claim record

The ransomware.live record identifies Southeastern Oklahoma State University as an Interlock-listed victim. Direct screenshots of Interlock’s branded leak page name the university and se.edu, allege a 710 GB collection containing 171,499 files and 19,366 folders, describe student and employee record categories, and show document thumbnails and a directory interface. The images document what Interlock claimed to possess and presented as available through its site, but do not establish that the alleged files are authentic, originated from the university or were downloadable in full.

See something that needs correction?

Signed-in members can report an error, update, or missing source.