Menu
Browse

Cyber Incident Victim: Pekin Community High School

Date:

Apr 2017

Location:

United States of America

Summary

Pekin Community High School experienced a significant ransomware attack that encrypted its computer systems, rendering critical data inaccessible and disrupting operations for students, teachers, and administrators. The attacker demanded a $37,000 ransom, which the district refused to pay, forcing the institution to temporarily operate without its technology-dependent resources while addressing the compromise.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Pekin Community High School in Illinois experienced a disruptive ransomware attack that began on Sunday, April 30, 2017, with the intrusion discovered by district officials the following Monday. The unidentified attacker deployed malware that encrypted critical computer systems, rendering them inaccessible to students, teachers, and administrators. District 303 Superintendent Danielle Owens confirmed the encryption prevented all access to stored information, paralyzing daily operations reliant on technology. The perpetrator demanded a ransom payment of $37,000 to restore system access, which school authorities explicitly refused to pay. Owens indicated the attack's origin remained unknown but suggested the possibility of involvement by a non-American entity. By Wednesday, three days after the initial compromise, the school community continued operating without computer access, significantly disrupting educational and administrative functions.

Cyber Incident Image

The sustained system outage forced the district to adapt manually, highlighting the institution's operational dependence on compromised technology. Owens publicly acknowledged the severity of the disruption on Wednesday, stating the incident demonstrated how quickly productivity stalled without technological resources. No restoration timeline or technical recovery details were disclosed publicly. The district maintained its non-negotiation stance regarding the ransom demand despite persistent operational challenges. Ongoing system inaccessibility affected all user groups equally, with no evidence suggesting data exfiltration beyond the encryption-based lockdown. School officials provided no updates regarding law enforcement involvement or forensic investigations into the attack's mechanisms. The incident remained unresolved at the time of reporting, with recovery efforts and total impact duration unconfirmed in available sources.

Sources
Sources available to members
1 source