Cyber Incident Victim: Hāwera High School
Date:
Jul 2018
Location:
New Zealand
Summary
A provincial high school experienced a ransomware attack where an anonymous hacker encrypted data containing students' coursework and teaching resources, demanding US$5000 for its release. The institution implemented a digital lockdown, taking its entire network offline as a precaution while staff relied on personal mobile hotspots or device data for limited operations; critical student and staff records remained unaffected. Police advised against complying with the ransom demand.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On Monday, July 30, 2018, staff at Hāwera High School in South Taranaki, New Zealand, discovered a ransom demand upon powering up their computers. An unidentified hacker had encrypted data stored on a school server containing students' coursework and teaching resources, blocking access to these materials. The attacker demanded a payment of US$5000 (approximately NZ$7400 at the time) in exchange for restoring access to the encrypted files. Principal Rachel Williams confirmed that the breach specifically targeted educational materials while leaving student and staff administrative records unaffected. The school immediately initiated a digital lockdown as a containment measure, taking the entire internal network offline to prevent further spread or data compromise. This action severed all standard network-dependent operations across campus.

The network shutdown forced staff to operate devices using alternative connectivity methods, including personal mobile data plans and smartphone hotspot connections. School administrators contacted New Zealand police, who advised against complying with the ransom demand. While the attack did not compromise sensitive personal records, it disrupted access to critical teaching resources and student assignments stored on the affected server. The incident required ongoing operational adjustments as the school maintained its offline status as a precautionary measure during the initial response phase. No additional details regarding the intrusion method, duration of network downtime, or final resolution were disclosed in available public reports.
