Cyber Incident Victim: Northwest Indian College
Timeline
Summary
Northwest Indian College experienced a significant cyberattack involving Ryuk ransomware, resulting in widespread corruption of internal files, backups, and legacy data. The college maintained limited operations during the incident, continuing face-to-face classes but suspending video conferencing services temporarily while working to secure its network. Authorities were notified, but no details regarding ransom demands or payment considerations were disclosed by the institution. The attack caused irreversible data loss, prompting the college to urge others to prioritize offsite or cloud backups for critical systems.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On or around July 11, 2019, Northwest Indian College (NWIC), the only accredited tribal college serving Washington, Oregon, and Idaho, experienced a significant cybersecurity incident involving Ryuk ransomware. The attack corrupted numerous internal files across the college’s systems, including backups and legacy data, rendering them irretrievably lost or damaged beyond repair. NWIC publicly confirmed the incident through a notice on its website, stating that services would be limited while the institution remained open during regular business hours. Face-to-face classes continued as scheduled, but hybrid courses relying on video conferencing were temporarily disrupted. The college contacted unspecified authorities to assist in determining next steps, while its IT staff worked to secure the network infrastructure. NWIC did not disclose whether a ransom demand was issued, the amount requested, or its decision-making process regarding potential payment. The public notice emphasized urging other community organizations to prioritize securing their networks and maintaining offsite or cloud backups of critical data.

The incident caused operational disruptions, though the extent of data loss beyond corrupted files remained unclear from available disclosures. NWIC’s statement acknowledged the irreversible damage to files but provided no technical specifics about the attack vector, duration of system compromise, or scope beyond references to backups and legacy data. No student or employee data breaches were explicitly reported. Recovery efforts focused on network security remediation rather than data restoration, suggesting the college accepted permanent loss of affected files. The college did not respond to external inquiries about consultation with cybersecurity experts or law enforcement agencies beyond initial notifications. Service limitations persisted during the response period, with no public timeline provided for full restoration of hybrid learning capabilities or other impacted systems. NWIC apologized for inconveniences but did not elaborate on long-term academic or administrative consequences stemming from the data loss.
