CSIDB logo
Incident

Cedar Rapids Community School District

Incident posture

Attack window
Jul 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-18 00:00

Linked entities

Victim
Cedar Rapids Community School District
Threat actors
0 actors
Sources
3 sources

Timeline

Occurred
Jul 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack on Cedar Rapids Community School District disrupted summer activities and compromised employee data including Social Security numbers, bank account details, and medical information. The district paid an undisclosed ransom after consulting cybersecurity experts and legal counsel to prevent potential data release, while offering affected staff a year of credit monitoring services. Internal IT and third-party specialists were engaged to restore systems and implement security improvements. The incident also caused cancellation of summer programs impacting hundreds of students.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Cedar Rapids Community School District (CRCSD) identified a cybersecurity incident on July 2, 2022, prompting an immediate district-wide closure and suspension of summer activities through July 8. Summer programming, including field trips, was canceled, affecting over 750 enrolled students, though high school baseball and softball games proceeded as scheduled. The district announced plans to resume regular operations by July 11. CRCSD engaged third-party cybersecurity experts and internal IT staff to investigate the breach, restore systems, and implement preventive measures. While initial communications did not disclose the attack’s nature or specific systems compromised, subsequent updates confirmed it involved unauthorized access to sensitive employee data.

Superintendent Noreen Bush confirmed in a letter to parents that CRCSD paid an undisclosed ransom to a third-party entity after consulting cybersecurity and legal advisors, aiming to prevent the release of accessed information. The compromised data included employees’ full names, Social Security numbers, driver’s license numbers, bank account and routing numbers, and medical details such as diagnoses, treatment records, and health insurance information. The district offered affected employees one year of complimentary credit monitoring services. Concurrently, the nearby Linn-Mar Community School District experienced a separate system disruption in early August 2022 but did not confirm whether it constituted a cyberattack or involved data theft. Cybersecurity experts noted schools’ frequent vulnerability due to limited funding for robust defenses, with national reports indicating 1,331 K-12 cybersecurity incidents since 2016 and ransomware costs exceeding $3.56 billion in 2021. The incident underscored operational disruptions, recovery expenses, and the diversion of resources from educational priorities during critical preparation periods for the academic year.

Sources

Sources available to members: 3 sources.

CSIDB