CSIDB logo
Incident

Hāwera High School

Incident posture

Attack window
Jul 2018
Location
New Zealand
Status
Historical
CIA posture
Available to members
Updated
2026-02-06 14:09

Linked entities

Victim
Hāwera High School
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A provincial high school experienced a ransomware attack where an anonymous hacker encrypted data containing students' coursework and teaching resources, demanding US$5000 for its release. The institution implemented a digital lockdown, taking its entire network offline as a precaution while staff relied on personal mobile hotspots or device data for limited operations; critical student and staff records remained unaffected. Police advised against complying with the ransom demand.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Monday, July 30, 2018, staff at Hāwera High School in South Taranaki, New Zealand, discovered a ransom demand upon powering up their computers. An unidentified hacker had encrypted data stored on a school server containing students' coursework and teaching resources, blocking access to these materials. The attacker demanded a payment of US$5000 (approximately NZ$7400 at the time) in exchange for restoring access to the encrypted files. Principal Rachel Williams confirmed that the breach specifically targeted educational materials while leaving student and staff administrative records unaffected. The school immediately initiated a digital lockdown as a containment measure, taking the entire internal network offline to prevent further spread or data compromise. This action severed all standard network-dependent operations across campus.

The network shutdown forced staff to operate devices using alternative connectivity methods, including personal mobile data plans and smartphone hotspot connections. School administrators contacted New Zealand police, who advised against complying with the ransom demand. While the attack did not compromise sensitive personal records, it disrupted access to critical teaching resources and student assignments stored on the affected server. The incident required ongoing operational adjustments as the school maintained its offline status as a precautionary measure during the initial response phase. No additional details regarding the intrusion method, duration of network downtime, or final resolution were disclosed in available public reports.

Sources

Sources available to members: 1 source.

CSIDB