Skip to content

Tulare City School District cybersecurity incident

Summary

Tulare City School District logo

Tulare City School District investigated suspicious cyber activity that disrupted computer systems and phone service in early February 2026. Phones were restored by Feb. 10 and broader system recovery was nearing completion; ransomware, data theft and SingularityMD attribution remain unconfirmed.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Educational operations disrupted

    Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Direct victim contact

    The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.

Incident narrative

Analyst assessment

Our reporting and subsequent Tulare City School District updates confirm with high confidence that the district experienced a cybersecurity incident. A purported extortion note signed SingularityMD remains a low-confidence actor claim because its origin was not independently verified and the district did not confirm ransomware, data theft or attribution.

Operational significance

The district said suspicious network activity affected the availability of certain computer systems and generated reports of suspicious emails. It later said district staff and third-party computer specialists were investigating while restoring full operability. Schools remained open, with no located closure or schedule change.

Recovery

On Feb. 10, the district said phone service was operating again and anticipated that all systems would be back online and fully functioning soon, although glitches remained possible. No later incident-specific closure notice was located, so the incident is presumed resolved; the exact full-restoration date remains unknown.

The impacted municipality is Tulare in Tulare County, California.

Confidence and uncertainty

Confidence is high that a cyber incident affected system and phone availability because the district documented the disruption and recovery work. Confidence remains low in ransomware, student-data theft and SingularityMD attribution because those assertions rely on unverified screenshots.

Disclosure posture

The district used cyber-specific suspicious-activity language and documented system availability and restoration effects, supporting organization-confirmed cyber and disruption transparency.

Analytic gaps

The public record does not establish initial access, malware, whether the extortion note was authentic, data access, ransom amount, notification population, actor or the exact final-restoration date. No California attorney general breach notice for the district was located through Sept. 16, 2026.

Organizations involved

Impacted locations

Source

Tulare school district investigates network incident

DysruptionHub reported the district disclosure and unverified screenshots of a note signed SingularityMD.

See something that needs correction?

Signed-in members can report an error, update, or missing source.