Claim details
Interlock listed Wagon Mound Public Schools and claimed it obtained about 80 GB of staff and student information. The district confirmed malware and operational disruption but has not corroborated Interlock, ransomware or data theft.
Wagon Mound Public Schools said a virus shut down district internet and networked computers around February 26, 2026, while its insurer worked to restore systems and staff and student devices were collected for scanning. Interlock listed the district March 9 and claimed it obtained about 80 GB of staff and student information, but the district has not confirmed ransomware, the actor or data theft. March 3 remains the last dated evidence of disruption, supporting presumed-resolved status without establishing an exact recovery date.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malicious software other than ransomware used to compromise or disrupt systems.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
A primary service, system, platform, or operational capability became entirely unavailable.
Internal or external network connectivity was unavailable or materially impaired.
The organization lost or materially restricted internet connectivity.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.
In the district’s official March newsletter, Superintendent Anita Romero told families that a virus had shut down internet and networked computers the preceding Thursday, indicating about Feb. 26. She said the district notified its insurer, which took immediate action and was working to restore systems; internet and computer use was prohibited, and staff and student computers were to be collected for scanning.
Interlock listed the district March 9 and claimed it obtained about 80 GB of staff and student information. The claim is concrete external cyber evidence but does not establish ransomware, actor responsibility or data theft. The district has not publicly corroborated those allegations.
DysruptionHub assesses with high confidence that malware caused a districtwide technology shutdown. Cyber involvement is confirmed by the district’s virus wording. Ransomware confidence remains medium and Interlock attribution remains low because both depend on the uncorroborated claim.
The shutdown removed internet and networked-computer access from a small PK-12 district and required staff and student devices to be collected for scanning. The letter did not say classes were canceled or facilities were closed because of the malware. It separately identified March 9-12 as scheduled spring break and said classes would resume March 16.
The district used cyber-specific wording March 3, before Interlock’s March 9 claim. That sequence supports organization-first cyber and disruption transparency.
March 3 remains the latest dated evidence that restoration was underway. No later public notice was found showing continuing disruption or giving a restoration date. With more than 30 days elapsed since the last observed impact, the incident is presumed resolved rather than confirmed resolved.
Confidence is high that the district experienced malware and a broad network disruption because Romero described both in the district’s letter. The public record does not independently substantiate Interlock’s 80 GB allegation or identify affected files or people.
The public record does not establish the malware family, initial access vector, compromised identity, malicious activity start, ransomware execution, Interlock responsibility, verified data theft, affected records, ransom demand, payment or exact restoration date. Threat-actor allegations are preserved as claims and do not by themselves establish responsibility, access scope, data provenance or payment.
Interlock listed Wagon Mound Public Schools and claimed it obtained about 80 GB of staff and student information. The district confirmed malware and operational disruption but has not corroborated Interlock, ransomware or data theft.

The superintendent said a virus infected district systems, forcing internet and networked computers offline while devices were scanned.
Superintendent Anita Romero said a virus had shut down district internet and networked computers the preceding Thursday. The insurer was working to restore service; internet and computer use was prohibited, and staff and student computers were to be collected for scanning.
Signed-in members can report an error, update, or missing source.