Skip to content

Suspected cyber incident closes Southeastern Oklahoma State campus for two days

The university took some computer systems offline after reporting a network disruption but has not confirmed the cause or disclosed a recovery timeline.

Blue letters spelling “Southeastern Oklahoma State University” mounted on a stone retaining wall, with grass and trees behind it.
A campus sign identifies Southeastern Oklahoma State University in Durant, Oklahoma, in June 2018. (Michael Barera/Wikimedia Commons)
Published:

Southeastern Oklahoma State University closed its Durant campus for two days and temporarily took some computer systems offline after reporting a network disruption affecting campus systems.

The university’s public notices reviewed by DysruptionHub described the incident only as a network disruption. KXII, citing the university, was the only source reviewed that attributed it to cybercriminals.

Screenshot of a Southeastern Oklahoma State University Facebook post announcing a network disruption affecting some campus systems and a campus closure for July 31 while IT staff worked to restore normal operations.
Southeastern Oklahoma State University said in a July 30 Facebook post that a network disruption was affecting some campus systems and that the university would remain closed July 31 while restoration work continued. (Southeastern Oklahoma State University/Facebook)

The closure interrupted in-person operations at the public university, which reported 6,012 students enrolled in full or partial fall 2025 terms. KXII reported that the university was investigating with help from third-party experts and working to determine the incident’s nature and scope.

Southeastern first announced the disruption in a Facebook post Thursday, July 30, and closed the campus for the rest of the day. An evening update extended the closure through Friday while information technology staff worked to restore normal operations.

The university did not specify which systems were taken offline.

The nature of the disruption remains unclear. There has been no public confirmation of ransomware, data theft, a ransom demand or law enforcement involvement.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

The university disruption comes about 14 months after a ransomware attack on Durant’s city government disrupted online payments and administrative systems. The city later said the attack may have exposed personal and financial information. No connection between the incidents has been reported.

DysruptionHub found no public claim of responsibility as of publication.

The university has not said when it expects to restore normal operations. It did not respond to a request for comment before publication.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
DysruptionHub Staff

DysruptionHub Staff

A collaborative project to bring you the latest cyberattacks impacting the availability of services and goods in the United States.

All articles

More in Education

See all

More from DysruptionHub Staff

See all