Tulare City School District

Tulare City School District investigated suspicious cyber activity that disrupted computer systems and phone service in early February 2026. Phones were restored by Feb. 10 and broader system recovery was nearing completion; ransomware, data theft and SingularityMD attribution remain unconfirmed.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.
The actor explicitly threatened to publish or publicly release victim data or incident details.
The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.
Our reporting and subsequent Tulare City School District updates confirm with high confidence that the district experienced a cybersecurity incident. A purported extortion note signed SingularityMD remains a low-confidence actor claim because its origin was not independently verified and the district did not confirm ransomware, data theft or attribution.
The district said suspicious network activity affected the availability of certain computer systems and generated reports of suspicious emails. It later said district staff and third-party computer specialists were investigating while restoring full operability. Schools remained open, with no located closure or schedule change.
On Feb. 10, the district said phone service was operating again and anticipated that all systems would be back online and fully functioning soon, although glitches remained possible. No later incident-specific closure notice was located, so the incident is presumed resolved; the exact full-restoration date remains unknown.
The impacted municipality is Tulare in Tulare County, California.
Confidence is high that a cyber incident affected system and phone availability because the district documented the disruption and recovery work. Confidence remains low in ransomware, student-data theft and SingularityMD attribution because those assertions rely on unverified screenshots.
The district used cyber-specific suspicious-activity language and documented system availability and restoration effects, supporting organization-confirmed cyber and disruption transparency.
The public record does not establish initial access, malware, whether the extortion note was authentic, data access, ransom amount, notification population, actor or the exact final-restoration date. No California attorney general breach notice for the district was located through Sept. 16, 2026.

DysruptionHub reported the district disclosure and unverified screenshots of a note signed SingularityMD.
Signed-in members can report an error, update, or missing source.