Alamo Heights Independent School District
Incident posture
Linked entities
- Victim
- Alamo Heights Independent School District
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
Alamo Heights Independent School District experienced a cyber attack that disrupted internet access for nearly a week and exposed personal information, including Social Security numbers and financial details, of about 26,000 individuals. The district notified affected individuals by U.S. mail in accordance with breach‑notification requirements and reported the incident to the Federal Bureau of Investigation. External forensic investigators assisted in restoring systems, after which day‑to‑day operations returned to normal. The district’s cyber insurance paid more than thirty‑six thousand dollars to cover restoration costs, and officials declined to confirm whether any ransom was paid. Throughout the response, the district provided updates to the community but did not disclose the full scope of the data accessed.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In late March 2026, Alamo Heights Independent School District experienced a cyber attack that began with connectivity problems noticed on March 23. On March 27 the district announced to families that the issue had been resolved and that district technology systems had been restored with the assistance of external forensic investigators, noting that the external threat no longer had access to the network and that the district had been walled off from the intrusion. The attack left staff and students without Internet access for nearly a week. During the weeklong outage and in the days that followed, district officials worked to restore systems and initiated an investigation into the breach. As part of the response, the district reported the incident to the Federal Bureau of Investigation. The district’s cyber insurance carrier subsequently paid more than $36,000 to cover system restoration costs, according to an email from the district’s chief financial officer obtained via a public records request.
Following the forensic investigation, Alamo Heights ISD determined that personal information had been accessed and potentially downloaded as a result of the attack, affecting approximately 26,000 individuals and including Social Security numbers and financial data. The district notified those impacted by U.S. mail in accordance with Texas breach‑notification requirements, which mandate reporting to the attorney general’s office within 30 days of discovery for incidents affecting 250 or more Texans. Throughout the incident, district officials kept community members updated but declined to provide details about the scope of the attack or confirm whether any specific personal information had been released. The spokeswoman repeatedly cited the ongoing investigation as the reason for not disclosing whether the district had paid a ransom to the attackers, and the district never confirmed a payment. The investigation remained active, with officials working to identify the full scope of the information involved.
The Alamo Heights incident fits a broader pattern of ransomware targeting Texas school districts; Judson ISD paid hackers a ransom of over $500,000 in 2021 after a month‑long attack that disabled phones, computers and email, while Uvalde CISD canceled classes for part of a week in September due to a separate attack. In response to the growing threat, Texas legislators passed Senate Bill 820 in 2019, requiring school districts to adopt cybersecurity policies, designate a cybersecurity coordinator, and establish a process for reporting breaches to the Texas Education Agency. The TEA launched a K‑12 Cybersecurity Initiative in 2023 to help districts prevent ransomware and phishing attacks, and lawmakers later approved an additional $42 million in funding to extend the initiative through 2027. Former FBI special agent William Odom, commenting on the case, said that paying a ransom does not guarantee data recovery, noting that attackers may provide incorrect decryption keys or demand additional payments after an initial payment. Odom also observed that a staff member could have clicked a link in an email that appeared legitimate, which is a common initial vector for such intrusions, and he emphasized that ransomware remains a real and continued threat to school systems, which serve a critical function but often lack the security measures of comparable for‑profit organizations.
Sources
Sources available to members: 2 sources.