CSIDB logo
Incident

Oklahoma City Public Schools

Incident posture

Attack window
May 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-04 00:00

Linked entities

Victim
Oklahoma City Public Schools
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Oklahoma City Public Schools experienced a significant ransomware attack that compromised the district's network. The malware infection worsened over time, leading to a confirmed disruption of systems and operational challenges. District officials acknowledged the severity of the incident as the cyberattack progressed, characterizing it as a substantial network compromise requiring ongoing response efforts.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Oklahoma City Public Schools (OKCPS) experienced a significant cybersecurity incident in mid-May 2019, confirmed as a ransomware attack. On Monday, May 13, 2019, the district publicly disclosed that its network had been "significantly compromised by a form of malware," characterizing the situation as actively deteriorating. The malware's impact escalated throughout that day, with district officials noting the issue was "continuing to worsen" in their initial communications. By the evening of Tuesday, May 14, OKCPS updated its assessment to specifically identify the malware as ransomware, marking the first official confirmation of the attack's nature. The incident disrupted normal network operations, though specific affected systems or services were not detailed in public statements. No information was provided regarding whether attackers encrypted data, made financial demands, or exfiltrated sensitive information during the intrusion.

The district initiated response protocols upon detecting the compromise, though technical specifics of containment measures were not disclosed. OKCPS maintained ongoing public communications through official statements during the initial crisis period, acknowledging the severity of the situation while continuing operational assessments. No evidence indicated the attack spread beyond OKCPS networks or impacted external partner systems. The district did not publicly confirm whether law enforcement agencies were involved in the investigation or whether third-party cybersecurity firms assisted in remediation efforts. Financial losses, recovery timelines, and academic disruptions resulting from the incident remained unspecified in available disclosures.

Sources

Sources available to members: 1 source.

CSIDB