CSIDB logo
Incident

Somerset Berkley Regional High School

Incident posture

Attack window
Jul 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-29 00:00

Linked entities

Victim
Somerset Berkley Regional High School
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jul 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Somerset Berkley Regional High School experienced a ransomware attack that encrypted portions of its computer systems, rendering them inoperable. The incident was confirmed by the superintendent in a communication to parents, noting the disruption to high school operations without specifying further details about data compromise or recovery efforts.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 17, 2020, Somerset Berkley Regional High School in Massachusetts experienced a ransomware attack that disrupted its computer systems. Superintendent Jeffrey Schoonover confirmed the incident in a formal letter addressed to parents, stating that unidentified threat actors had successfully encrypted portions of the high school's digital infrastructure. The encryption rendered affected systems inoperable, directly impairing administrative and operational functions reliant on those compromised devices. The attack specifically targeted the regional high school's network rather than the broader district infrastructure. No details were disclosed regarding the initial attack vector, specific ransomware variant used, or whether student or employee data was exfiltrated during the breach.

The school administration acknowledged the operational disruption caused by the system encryption but did not specify which departments or services were most severely impacted. Schoonover's notification provided no information about containment measures, forensic investigations, or system recovery timelines implemented by the district. The letter served as the primary public communication regarding the incident, with no supplementary statements or updates referenced in available sources. Further details about the attack's technical scope, financial demands from threat actors, or negotiated resolutions were reported exclusively by the Taunton Daily Gazette, though specific contents from that publication remain unspecified in the source material. The incident marked a confirmed cybersecurity disruption affecting educational operations during the 2020 summer period.

Sources

Sources available to members: 1 source.

CSIDB