Skip to content

Cyberattack damages files at Salida School District in Colorado

The district shut down its network and said some locally stored files could not be recovered, while cloud-based systems remained available.

Purple-and-white metal sign reading “Salida Schools Administration” outside the district’s central office.
A sign marks Salida School District’s central administration office at 627 Oak St. in Salida, Colorado. (Salida School District)

A cyberattack forced Salida School District in Colorado to shut down its network June 29, damaging locally stored files and disrupting administrative operations, the district said.

The attack began about 6:30 a.m. and was detected two hours later, according to a July 2 district notice. Officials took all systems offline and brought in specialists to investigate the incident and plan a safe restoration.

Some devices connected to the network suffered damage to files stored on their hard drives. “Some damaged files will not be able to be recovered,” district communications assistant Kim LeTourneau wrote in the notice. The damage disrupted work at the district’s central office.

The district said its cloud-based systems remained operational. It instructed staff not to turn on district desktops or laptops until the technology team had evaluated them.

Screenshot of a July 2, 2026, Salida School District notice stating that a cyberattack prompted a network shutdown, damaged files on some devices and did not appear to result in data access or extraction.
A July 2 notice from Salida School District says a June 29 cyberattack damaged locally stored files and prompted officials to shut down the district’s network. (Salida School District)

Salida School District R-32-J is a public school system serving students in prekindergarten through 12th grade in parts of Chaffee and Fremont counties. Federal data for 2024-25 list six schools and about 1,350 students.

The Salida attack follows a January 2025 network disruption at Aurora Public Schools that was later claimed by the Fog ransomware group. Aurora shut down districtwide internet and phone service after detecting suspicious network activity. Fog alleged that it stole 171 GB of data, but the district did not publicly confirm the attribution or claimed theft.

The district reported the attack to law enforcement and said an investigation was ongoing. “It appears that no information or data was accessed or extracted,” LeTourneau wrote. As of publication, the district had not released final forensic findings confirming that preliminary assessment.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

At the time of the disclosure, the district said no information appeared to have been accessed or extracted. It has not published final forensic findings confirming that preliminary assessment.

The district also has not said whether the attack involved ransomware or extortion. No threat actor has been publicly linked to the incident, and the attack method and initial point of access remain unknown.

Officials credited network and infrastructure upgrades completed during the previous two years with limiting the damage. The district said the incident would accelerate several additional upgrades already under consideration.

Later district communications describe routine activity for the 2026-27 school year and do not identify continuing system outages. However, the district has not published an explicit technical all-clear or an exact restoration date.

The district did not respond to DysruptionHub’s request for comment by publication time.

Joseph Topping

Joseph Topping

Joseph Topping is the founder and editor of DysruptionHub, reporting on cyber incidents and technology failures that disrupt public services, organizations and daily life.

All articles

More in Education

See all

More from Joseph Topping

See all