Skip to content

Wagon Mound Public Schools malware incident

Summary

Wagon Mound Public Schools logo

Wagon Mound Public Schools said a virus shut down district internet and networked computers around February 26, 2026, while its insurer worked to restore systems and staff and student devices were collected for scanning. Interlock listed the district March 9 and claimed it obtained about 80 GB of staff and student information, but the district has not confirmed ransomware, the actor or data theft. March 3 remains the last dated evidence of disruption, supporting presumed-resolved status without establishing an exact recovery date.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Malware

    Malicious software other than ransomware used to compromise or disrupt systems.

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

Operational impacts

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

Incident narrative

Analyst assessment

In the district’s official March newsletter, Superintendent Anita Romero told families that a virus had shut down internet and networked computers the preceding Thursday, indicating about Feb. 26. She said the district notified its insurer, which took immediate action and was working to restore systems; internet and computer use was prohibited, and staff and student computers were to be collected for scanning.

Interlock listed the district March 9 and claimed it obtained about 80 GB of staff and student information. The claim is concrete external cyber evidence but does not establish ransomware, actor responsibility or data theft. The district has not publicly corroborated those allegations.

DysruptionHub assesses with high confidence that malware caused a districtwide technology shutdown. Cyber involvement is confirmed by the district’s virus wording. Ransomware confidence remains medium and Interlock attribution remains low because both depend on the uncorroborated claim.

Operational significance

The shutdown removed internet and networked-computer access from a small PK-12 district and required staff and student devices to be collected for scanning. The letter did not say classes were canceled or facilities were closed because of the malware. It separately identified March 9-12 as scheduled spring break and said classes would resume March 16.

Disclosure posture

The district used cyber-specific wording March 3, before Interlock’s March 9 claim. That sequence supports organization-first cyber and disruption transparency.

Current status

March 3 remains the latest dated evidence that restoration was underway. No later public notice was found showing continuing disruption or giving a restoration date. With more than 30 days elapsed since the last observed impact, the incident is presumed resolved rather than confirmed resolved.

Confidence and uncertainty

Confidence is high that the district experienced malware and a broad network disruption because Romero described both in the district’s letter. The public record does not independently substantiate Interlock’s 80 GB allegation or identify affected files or people.

Analytic gaps

The public record does not establish the malware family, initial access vector, compromised identity, malicious activity start, ransomware execution, Interlock responsibility, verified data theft, affected records, ransom demand, payment or exact restoration date. Threat-actor allegations are preserved as claims and do not by themselves establish responsibility, access scope, data provenance or payment.

Threat actor and claim

Listed as: Wagon Mound Public SchoolsSource: ransomware.livePublished:

Claim details

Interlock listed Wagon Mound Public Schools and claimed it obtained about 80 GB of staff and student information. The district confirmed malware and operational disruption but has not corroborated Interlock, ransomware or data theft.

Organizations involved

Impacted locations

Sources

Wagon Mound schools shut network after virus

The superintendent said a virus infected district systems, forcing internet and networked computers offline while devices were scanned.

March Newsletter 2026

Superintendent Anita Romero said a virus had shut down district internet and networked computers the preceding Thursday. The insurer was working to restore service; internet and computer use was prohibited, and staff and student computers were to be collected for scanning.

See something that needs correction?

Signed-in members can report an error, update, or missing source.