Cyber Incident Victim: Evanston Township High School
Date:
Jul 2026
Location:
United States of America
Summary
Evanston Township High School experienced a ransomware attack that forced a two‑day campus shutdown, disrupted phone service for several weeks and later impacted its parking lottery allocation system. Weeks after that incident, several students received phishing emails that appeared to come from a compromised student account, offered part‑time work and requested personal information; the district removed the messages, disabled the account and stated the phishing effort was unrelated to the earlier ransomware event.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 3 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On June 7, Evanston Township High School experienced a ransomware attack that forced the campus to close for two days and disrupted phone service, which remained unavailable until June 26. The ransomware, defined as malicious software that blocks access to systems or data until a ransom is paid, is still under investigation. In addition to the immediate disruptions, the school later announced that the same summer cybersecurity incident had affected its parking lottery system, which allocates on‑campus parking spaces to eligible students. Approximately six weeks after the June 7 attack, in mid‑July, several students to eligible students. Approximately six weeks after the June 7 attack, in mid‑July, several students began receiving phishing emails that appeared to come from a compromised student ETHS email account. The article reporting these events was published on July 23, 2026.

The phishing messages offered part‑time work paying $550 for two to three hours, three times a week, and were signed by “Human Resource” at Evanston Township High School. Each email contained a link that directed recipients to a site requesting personal information such as passwords or account numbers. Upon discovery, District 202 spokesperson Reine Hanna stated that the district removed the messages from its systems on Tuesday and suspended the compromised email account. Hanna emphasized that the phishing incident was not connected to the June 7 ransomware attack and characterized it as a routine cybersecurity matter, noting that students and staff regularly receive guidance on identifying and reporting suspicious messages. The June 7 ransomware attack remains under investigation, and its broader impacts, including the phone service outage and parking lottery disruption, continue to be addressed.
