Skip to content

Suspected cyberattack disrupted Northwest Iowa Community College

Northwest Iowa Community College canceled on-campus classes and restored systems before disclosing more than seven months later that investigators found unauthorized activity during the disruption.

Sign for Northwest Iowa Community College on the campus in Sheldon, Iowa, with a college building and trees in the background.
The Northwest Iowa Community College campus sign outside the college in Sheldon, Iowa. (Northwest Iowa Community College)

A suspected cyberattack disrupted Northwest Iowa Community College’s network for nearly two weeks in November and December, canceling on-campus classes and disrupting technology services.

More than seven months later, the college publicly disclosed for the first time that the incident involved unauthorized activity and that information may have been accessed or downloaded between Nov. 24 and Nov. 26, 2025. On Nov. 29, three days after that period ended, the college described the problem only as technical issues affecting Wi-Fi and other on-campus systems.

The incident began during the college’s Thanksgiving break, which ran from Nov. 26 through Nov. 30. Public statements do not establish when systems first became unavailable or whether the break delayed recognition of the disruption or the need to disclose its operational impact.

Northwest Iowa Community College is a public two-year college near Sheldon that serves students across northwest Iowa.

In a Nov. 29 Facebook post, the college said MyPlace, Canvas, Wi-Fi and other digital systems were inaccessible on campus because of technical issues. It said most services remained available off campus except email.

Screenshot of a Facebook post from Northwest Iowa Community College announcing that MyPlace, Canvas, Wi-Fi and other digital systems were offline on campus because of technical issues. A Dec. 9 reply from the college states that most systems, including Wi-Fi, email and printing services, were operating normally, with only a few remaining services still being restored.
Screenshot of a Nov. 29, 2025, Facebook post from Northwest Iowa Community College stating that on-campus digital systems were offline because of technical issues. In a Dec. 9 reply to a comment, the college said most campus systems had been restored.

On Dec. 1, the college said its information technology staff and security tools had detected and contained a computer network disruption. It also said federal law enforcement and forensic specialists were assisting with the response, but it did not disclose that unauthorized activity had been discovered or that personal information may have been accessed.

Over the following week, the college gradually restored services. By Dec. 8, Wi-Fi, limited email access and printing had returned, while Self-Service remained unavailable. In a Dec. 9 Facebook response, the college said most systems were operating normally. On Dec. 11, it said most remaining services, including Self-Service, had been restored, although some systems were still stabilizing.

The college said it discovered unauthorized activity Nov. 26 and hired outside specialists to investigate. The investigation determined that a limited amount of information may have been accessed or downloaded between Nov. 24 and Nov. 26. After completing its review of potentially affected records May 29, the college began mailing notices July 8 to 16,004 Iowa residents whose names and Social Security numbers may have been involved.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

The disclosure timeline differs from many recent higher education cyber incidents, where colleges publicly identified suspected cyberattacks or unauthorized network activity as operational disruptions unfolded. Northwest Iowa Community College publicly disclosed the disruption in late November and early December but did not reveal until July that investigators had identified unauthorized activity during the incident.

Northwest Iowa Community College said it secured its network, conducted a forensic investigation, and reviewed and strengthened its data security policies and procedures. It offered affected people 12 months of credit monitoring and fraud assistance.

The college has not disclosed the method of intrusion, whether ransomware or extortion was involved, or whether the potentially affected information was misused. No threat actor has been identified, and no ransom demand has been disclosed.

DysruptionHub asked the college whether the November outages were caused by the unauthorized activity, when systems first became unavailable, and whether the Thanksgiving break affected when the disruption became apparent. A response was not immediately available.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
DysruptionHub Staff

DysruptionHub Staff

A collaborative project to bring you the latest cyberattacks impacting the availability of services and goods in the United States.

All articles

More in Education

See all

More from DysruptionHub Staff

See all