CSIDB logo
Incident

Lake Oswego School District

Incident posture

Attack window
Jul 2020
Location
Russia
Status
Historical
CIA posture
Available to members
Updated
2025-10-30 00:00

Linked entities

Victim
Lake Oswego School District
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jul 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Moses Lake School District, comprising 16 schools, suffered a ransomware attack originating from a phishing email sent from an IP address in Moscow, Russia. The attackers demanded a $1 million ransom, which the district refused to pay. The incident compromised data integrity and confidentiality, leading to the rebuilding of over 50 servers and PCs using backups. The attack disrupted the district's operations, forcing it offline for more than two weeks.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Moses Lake School District, encompassing 16 schools in Washington, experienced a disruptive ransomware attack in July 2020. The incident began when a phishing email containing malicious content reached district systems. Forensic analysis traced the attack’s origin to an IP address located in Moscow, though no specific threat actor group was identified in available reporting. The ransomware encrypted critical infrastructure, rendering systems inaccessible and forcing the district offline. Administrators discovered that the attackers demanded a $1 million ransom payment to restore access to the encrypted data. District leadership declined to negotiate with or pay the ransom demand, opting instead to rely on internal recovery processes.

The district’s recovery efforts involved rebuilding more than 50 affected servers and workstations over a period exceeding two weeks. Restoration relied exclusively on backup data, with some backups being up to five months old at the time of the attack. This restoration timeframe resulted in prolonged operational disruptions across academic and administrative functions. No confirmed data exfiltration or student information compromise was disclosed in the examined source material. The incident underscored infrastructure vulnerabilities associated with phishing vectors and highlighted the operational consequences of dependency on outdated backups during cyber recovery scenarios. The district resumed normal operations after completing system restoration without fulfilling the attackers’ financial demands.

Sources

Sources available to members: 1 source.

CSIDB