Skip to content

Krum, Texas, library ransomware disrupted computers, Wi-Fi

NightSpire later claimed it was selling 50 GB of library data, but officials have not confirmed the group’s claim.

Exterior wall of Krum Public Library in Texas, with the library name and address displayed on brick.
Krum Public Library in Krum, Texas. (Krum Public Library)
Published:
Update, June 6: After publication, the NightSpire ransomware group listed Krum Public Library on its leak site, claiming to sell 50 GB of data allegedly taken from the library. The listing described the data as financial documents, HR data and supervisor information and was dated May 15. DysruptionHub viewed the listing, but could not independently verify the group’s claims or whether the data came from Krum Public Library.

Krum Public Library in Texas said computer access, printing and Wi-Fi were temporarily down after a May 14 ransomware attack, with checkout limited to five items.

The outage affected basic public library technology services before the city disclosed that the incident was ransomware. Krum is a Denton County city in the Dallas-Fort Worth area with an estimated 2025 population of 6,808.

Krum Public Library posted May 15 that “computer access, printing capability, and WiFi” were temporarily down and that checkout would be limited to five items, according to a library Facebook post.

Screenshot of a Krum Public Library Facebook post saying computer access, printing and Wi-Fi were temporarily down and checkout was limited to five items.
A Krum Public Library Facebook post on May 15 said computer access, printing and Wi-Fi were temporarily down and checkout was limited to five items. (Krum Public Library)

The disruption came one day after the library said it detected unusual activity on its computer network May 14. In a June 3 public notification, the city said the library had confirmed it was the victim of a “sophisticated ransomware attack” carried out by cybercriminal threat actors.

The library also said in an FAQ that the attackers demanded an extortion payment and could retaliate by publishing data they claimed to have stolen. The library said it believed resources were better spent preventing another incident.

After publication, the NightSpire ransomware group listed Krum Public Library on its leak site, claiming to sell 50 GB of data allegedly taken from the library. The listing described the data as financial documents, HR data and supervisor information and was dated May 15. DysruptionHub viewed the listing, but could not independently verify the group’s claims or whether the data came from the library. Krum Public Library had not responded to an emailed request for comment by the time of publication.

Screenshot of a NightSpire leak-site listing claiming Krum Public Library data was for sale, with another listed victim blurred out.
A NightSpire leak-site listing claims Krum Public Library data was for sale, including financial documents, HR data and supervisor information. The listing’s claims have not been independently verified. (Screenshot by DysruptionHub)

The city said the attack was limited to the library environment and did not affect the broader city network or other city operations or services. The library said its network was secured and there has been no further unauthorized access.

The library said it did not permanently lose critical data because of backup technology and support from the city’s IT team and a managed services provider. A forensic investigation found that some files on the library network were accessed without authorization, and officials said they are reviewing those files to determine whether sensitive personal information was involved.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

Krum officials said no Social Security numbers or personal financial account information belonging to employees, patrons or others were affected. The library said it was not aware of fraud or misuse tied to the incident and would notify potentially affected people if the file review identifies sensitive personal information.

The city said it notified federal law enforcement, including the FBI and Department of Homeland Security. The library said it was establishing a dedicated phone line for residents, employees and others with questions about the incident.

The Krum incident follows other cyber disruptions at public libraries. Fort Bend County Libraries in Texas said a February 2025 cybersecurity incident affected some services, including catalog and e-library access, and the county later approved nearly $2.6 million in cybersecurity contracts. Kent District Library in Michigan said an April 2026 ransomware event affected some systems and services, temporarily leaving public computers, printing and other branch technology unavailable or limited.

No threat actor was named in Krum’s notice. After publication, NightSpire claimed responsibility on its leak site, but officials have not confirmed a threat actor, said what systems were encrypted, disclosed how long the technology outage lasted or said whether any data has been published. The city said the library network is secure and broader city services were not affected.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
DysruptionHub Staff

DysruptionHub Staff

A collaborative project to bring you the latest cyberattacks impacting the availability of services and goods in the United States.

All articles

More in Public Services

See all

More from DysruptionHub Staff

See all