A suspected cyberattack disrupted Northwest Iowa Community College’s network for nearly two weeks in November and December, canceling on-campus classes and disrupting technology services.
More than seven months later, the college publicly disclosed for the first time that the incident involved unauthorized activity and that information may have been accessed or downloaded between Nov. 24 and Nov. 26, 2025. On Nov. 29, three days after that period ended, the college described the problem only as technical issues affecting Wi-Fi and other on-campus systems.
The incident began during the college’s Thanksgiving break, which ran from Nov. 26 through Nov. 30. Public statements do not establish when systems first became unavailable or whether the break delayed recognition of the disruption or the need to disclose its operational impact.
Northwest Iowa Community College is a public two-year college near Sheldon that serves students across northwest Iowa.
In a Nov. 29 Facebook post, the college said MyPlace, Canvas, Wi-Fi and other digital systems were inaccessible on campus because of technical issues. It said most services remained available off campus except email.

On Dec. 1, the college said its information technology staff and security tools had detected and contained a computer network disruption. It also said federal law enforcement and forensic specialists were assisting with the response, but it did not disclose that unauthorized activity had been discovered or that personal information may have been accessed.
Over the following week, the college gradually restored services. By Dec. 8, Wi-Fi, limited email access and printing had returned, while Self-Service remained unavailable. In a Dec. 9 Facebook response, the college said most systems were operating normally. On Dec. 11, it said most remaining services, including Self-Service, had been restored, although some systems were still stabilizing.
The college said it discovered unauthorized activity Nov. 26 and hired outside specialists to investigate. The investigation determined that a limited amount of information may have been accessed or downloaded between Nov. 24 and Nov. 26. After completing its review of potentially affected records May 29, the college began mailing notices July 8 to 16,004 Iowa residents whose names and Social Security numbers may have been involved.
The disclosure timeline differs from many recent higher education cyber incidents, where colleges publicly identified suspected cyberattacks or unauthorized network activity as operational disruptions unfolded. Northwest Iowa Community College publicly disclosed the disruption in late November and early December but did not reveal until July that investigators had identified unauthorized activity during the incident.
Northwest Iowa Community College said it secured its network, conducted a forensic investigation, and reviewed and strengthened its data security policies and procedures. It offered affected people 12 months of credit monitoring and fraud assistance.
The college has not disclosed the method of intrusion, whether ransomware or extortion was involved, or whether the potentially affected information was misused. No threat actor has been identified, and no ransom demand has been disclosed.
DysruptionHub asked the college whether the November outages were caused by the unauthorized activity, when systems first became unavailable, and whether the Thanksgiving break affected when the disruption became apparent. A response was not immediately available.