Menu
Browse

Cyber Incident Victim: Oglethorpe County School System

Date:

Nov 2020

Location:

United States of America

Summary

A ransomware attack disrupted Oglethorpe County Schools' computer and phone systems, forcing closure for multiple days and extending through the Thanksgiving break. The incident caused significant operational disruption, halting in-person classes and administrative functions. No specific ransomware variant or responsible threat actors were identified at the time of reporting, and the district had not appeared on known ransomware leak sites. The attack's impact persisted beyond initial closure dates due to scheduled holiday downtime.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On or around November 19, 2020, Oglethorpe County Schools in Georgia experienced a disruptive ransomware attack that forced the rural school system to cancel classes. The attack compromised the district’s computer and phone systems, rendering them inoperable and prompting school officials to close facilities on Thursday, November 19, and Friday, November 20. Unlike previous closures primarily linked to COVID-19 concerns, this shutdown stemmed directly from the cyber incident. Students were scheduled to remain out of class until at least November 30 due to the coinciding Thanksgiving holiday break, extending the operational disruption. The attack disrupted critical infrastructure, though specific affected systems beyond phones and computers were not detailed in available reports. No ransomware variant or threat actor group was identified in initial disclosures, and the district had not appeared on any dedicated ransomware leak sites monitored by security researchers at the time of reporting.

Cyber Incident Image

The school district communicated the incident through a Facebook post but did not publish a notice on its official website as of the reporting date. Recovery timelines and technical containment measures were not publicly disclosed. The attack’s operational impact included sustained system downtime and an extended cessation of in-person instruction, though remote learning alternatives were not mentioned. No data theft or leakage claims by threat actors were corroborated in available sources. The district’s reliance on social media for incident communication contrasted with its primary web presence, which remained inactive regarding the breach. Cybersecurity observers noted the absence of ransomware group attribution but emphasized the prevalence of unaffiliated or emerging threat actors beyond the dozen groups commonly tracking leak sites.

Sources
Sources available to members
1 source