Cherokee County School District
Incident posture
Linked entities
- Victim
- Cherokee County School District
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
A network security incident disrupted Cherokee County School District in South Carolina, prompting the interim superintendent to advise students and staff against logging in or connecting to district systems while the breach was investigated. Officials coordinated with the FBI, the State Law Enforcement Division, and the Cherokee County Sheriff's Department to determine the cause and scope of the intrusion, and the district stated there were no additional dangers associated with the breach. The incident was later attributed to the ransomware group Interlock, which has increasingly targeted U.S. K-12 schools, and resulted in approximately 46,000 records being exposed as part of broader campaign activity against the education sector.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
A network security incident was reported in the Cherokee County School District in March 2025, disrupting the district's computer systems and prompting immediate coordination with multiple law enforcement agencies. The County Interim Superintendent confirmed the breach, and the district began working with the Federal Bureau of Investigation (FBI), the State Law Enforcement Division (SLED), and the Cherokee County Sheriff's Department to determine both the cause and the extent of the intrusion. As a precaution, officials advised students and staff to avoid logging in to or otherwise connecting to the school district's network while the situation was being assessed. Dr. Thomas White Jr., the Interim Superintendent for the Cherokee School District, stated publicly that "the security of our students, staff, and community is our highest priority" and that the district was "working diligently with state law enforcement and cybersecurity experts to address this matter." District officials indicated at that time that they believed there were no other dangers associated with the breach beyond the immediate network impact that had been identified.
The incident was later attributed to the ransomware group Interlock, which was responsible for several K-12 breaches in 2025 and was reported as having significantly expanded its activity against U.S. schools compared to prior years. According to Comparitech's education ransomware roundup, Interlock was linked to an attack on Cherokee County School District in Georgia affecting approximately 46,000 records, making it one of the year's largest K-12 breaches. Comparitech's data research team noted that the group had grown its presence in education from two attacks in 2024 to seventeen attacks in 2025, and characterized Interlock as clearly targeting U.S. schools and successfully stealing significant volumes of data from school districts. The Cherokee County incident, as confirmed by the targeted organization, was therefore part of a broader pattern of K-12 targeting that year, in which K-12 institutions accounted for the majority of education-sector ransomware incidents, with U.S. K-12 attacks numbering 96 compared to 34 in higher education. While K-12 represented the largest share of attack frequency, the article notes that the total number of exposed records at the K-12 level in the U.S. for 2025 reached 175,000 — a figure that, although substantial, was considerably lower than the 3.7 million records exposed in higher-education breaches during the same period, driven largely by third-party software vulnerabilities rather than direct K-12 targeting.
Sources
Sources available to members: 2 sources.