Onslow County Schools in North Carolina said a June 9 cyberattack disrupted phones and internet districtwide, affecting End-of-Course retesting and graduation livestreams.
The district’s confirmation changed what it first described publicly as a “technical issue” into a confirmed criminal cyberattack under law enforcement investigation. OCS reported the phone and internet outage Tuesday evening, June 9, but did not publicly classify it as a cybersecurity incident until Saturday, June 13, after DysruptionHub had asked the district directly whether cybersecurity was involved.

The district serves Onslow County on North Carolina’s southeastern coast, including the Jacksonville and Camp Lejeune area, and is the state’s 11th-largest school system, with more than 28,000 students across 43 educational facilities.
Onslow County Schools said it detected unauthorized criminal activity in its technology infrastructure in the early morning hours of Tuesday, June 9. District technology staff began taking protective action and notified law enforcement and state cybersecurity authorities, according to an incident update posted by the district.
The district said the cyberattack is under active investigation by OCS technology staff in coordination with local, state and federal law enforcement, including the North Carolina Joint Cybersecurity Task Force, the FBI and the U.S. Secret Service.

The attack disrupted phone and internet services across the district. Onslow County Schools initially told families that a “technical issue” had made phones and internet unavailable at all OCS locations and that there was no estimated timeframe for full restoration.
The outage affected several operations, including End-of-Course retesting and graduation livestreaming, WCTI reported. In district notices, OCS said some ceremonies might not be livestreamed and that recordings would be posted later if livestreams were unavailable.
OCS has confirmed a cybersecurity incident, but it has not publicly identified the attack type. Officials have not said whether ransomware, malware, data theft, extortion or a third-party vendor was involved. DysruptionHub found no public ransomware claim tied to OCS before the district’s confirmation.

Before the district’s June 13 confirmation, DysruptionHub asked OCS about the outage’s cause, timeline, affected systems, recovery status and whether cybersecurity was involved. The district did not respond before the original story was published.
The district said it is committed to protecting the privacy and security of students, families and staff and is taking steps to investigate and respond. It directed families to its website for updates.
Other school districts have taken days or weeks to publicly connect broad technology outages to cyber incidents. Alamo Heights Independent School District near San Antonio initially reported Gmail, Wi-Fi and internet disruptions in March before later confirming ransomware caused the multiday outage. Belgrade schools in Montana faced parent questions and speculation after trustees approved $750,000 for network security and restoration services in April, before the district later said malware had affected network systems and that a review of possible student and staff data exposure was underway.
As of the district’s latest public update, the incident remained under active investigation. Officials had not announced a full restoration timeline or said whether any student or employee data was exposed.
OCS said it will continue posting updates as the investigation and recovery continue. No ransomware group, data theft or ransom demand has been confirmed.