Spokane Public Schools in Washington shut down access to PowerSchool, its payroll system and other online services after detecting a network security incident Sunday night, forcing teachers to use manual workarounds.
Superintendent Adam Swinyard said a district reporting system flagged the incident Sunday night. Personnel were working on-site within hours, and the district brought in a third-party technical expert to investigate, according to The Spokesman-Review.
The district notified families Monday that it had taken several systems offline as a precaution. It warned that requests for information from teachers and other staff could be disrupted.
PowerSchool, which the district uses for attendance and communication with families, was among the unavailable programs. Teachers shifted to manual processes, while Swinyard encouraged parents and guardians seeking information to contact staff by email or telephone.
The district’s payroll system was also offline Tuesday. Officials have not reported that scheduled payments were missed, and they have not provided a complete list of affected systems.
Swinyard said investigators had so far identified district staff as the only people affected and that staff members had been notified. He said it was too early to determine the extent of affected information or who may have been responsible.
The district planned to keep the systems offline until investigators determined they could be restored safely. Officials did not report school closures or interruptions to classroom instruction, transportation or other school operations.
By contrast, a cyber incident earlier this month led Springfield Public Schools in Massachusetts to close all 64 schools for four days. Classes resumed Sept. 14 after critical safety and communication functions were restored, though some technology workarounds and the investigation continued.
Spokane officials have not said how the incident began, whether anyone gained unauthorized access or whether data was accessed or copied. The district also has not identified ransomware, extortion or a responsible actor, and it has not provided a restoration timeline.