Cyber Incident Victim: Oceanside Unified School District
Timeline
Summary
Oceanside Unified School District experienced a cyberattack that compromised its network, disrupting email, internet, Google Drive and Classlink access for staff and affecting school registration and payroll processes. The district, which employs about 1,500 people and serves over 15,000 students across 21 schools and an adult transition academy, worked with IT staff and third‑party forensic specialists to contain the incident and restore services, while the FBI was notified due to concerns about potential exposure of military‑related information from three schools located on Camp Pendleton.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Sources inside the district confirmed OUSD has been working to contain the attack since July 24. The district’s network has been compromised, and the district is working with "cybersecurity experts" to conduct an investigation and return the systems to normal, Superintendent Julie Vitale said. Vitale said work email, internet, Google Drive and any programs via Classlink are temporarily unavailable. Vitale said the district and cybersecurity experts are working to restore network services as fast as possible. Vitale said an update will be provided once more information is available. OUSD is one of the city’s largest employers with about 1,500 employees, more than 15,000 students across 21 schools and one adult transition academy, according to the district website. It’s unknown what the threat actors have targeted, but the attack was apparently elevated to the FBI, sources said. Additionally, three of OUSD’s schools — North Terrace, Stuart Mesa and Santa Margarita — are located on Camp Pendleton, which has raised concerns about potentially compromised information about military personnel whose kids are enrolled in OUSD schools, the sources said. FBI representatives in Washington, D.C. and San Diego declined to comment.

"OUSD recently discovered a computer network disruption and immediately began working with our IT staff and third-party forensic specialists to investigate the nature and scope of the incident," OUSD Director of Communications Donald Bendz said. "Our investigation is ongoing, and we are unable to provide further details at this time. We appreciate your patience as we continue to investigate this matter," Bendz said. Sources said it’s unknown how the network was compromised. One source said district staff was working furiously to "pull the plugs" because staff believed hackers were taking information from "the district database." Another source said the district should notify families as attackers are wreaking havoc on registration, as it could be another two weeks before the network is back up. School registration opens Monday, a source said. Teachers, meanwhile, return to the classroom on Aug. 7 to prepare for the upcoming 2026-27 school year, the sources said, while school starts on Aug. 13. "We recently identified an incident that disrupted the use of our network," according to a message sent to some employees from OUSD Director of Communications Donald Bendz on Tuesday. "We anticipate our network will be down for the rest of the week. This means you will not be able to access your email, internet, or our programs via Classlink." One source said the cyberattack may also jeopardize the district’s payroll, as employees are scheduled to be paid today. A mass text message from the district on Sunday night confirmed the incident was a cyberattack and that the district’s internet was disrupted and was later confirmed to be offline, per Bendz’s message. The message said phones would work and for employees to continue a regular workday. It’s unclear from the sources how employees from the district administration, teachers and classified employees were impacted.
According to the U.S. Department of Education, school districts experience an average of five cyberattacks per week. The two most common attacks are direct attacks on a district’s network and third-party or vendor breaches. The district is working with cybersecurity experts to conduct an investigation and return the systems to normal. An update will be provided once more information is available.
