Cyber Incident Victim: Newhall School District
Date:
Sep 2020
Location:
United States of America
Summary
A ransomware attack disrupted the Newhall School District's network, forcing cancellation of online classes for two consecutive days. The incident disabled critical systems, including email services, while educators provided non-technological lesson plans. District administrators engaged legal and insurance teams to investigate and resolve the breach, mirroring a similar cybersecurity incident affecting another local school system weeks prior.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The Newhall School District experienced a disruptive ransomware attack over the weekend of September 12-13, 2020, forcing the cancellation of all online classes on Monday, September 14. District officials announced via Instagram early Monday that the attack had disabled their network infrastructure, making virtual instruction impossible. By Monday evening, the district confirmed classes would remain canceled on Tuesday, September 15, as technical issues persisted. Superintendent Jeff Pelzel notified parents through a formal letter explaining the ongoing network outages and the inability to restore systems within the first 48 hours. The attack compromised critical IT resources, including the district's email server, severing primary communication channels between staff and families.

Response efforts involved coordinated actions with the district's legal counsel and insurance provider to investigate the breach and negotiate recovery options. Pelzel emphasized restoration priorities while directing teachers to develop non-digital lesson plans to maintain educational continuity without network dependencies. The incident mirrored cybersecurity challenges faced by other Southern California districts, including Rialto Unified School District's malware-related shutdown in August 2020. No ransom demands, payment details, or specific threat actor information were disclosed publicly. The district maintained operational focus on containing the attack's spread and minimizing academic disruption through alternative teaching methods during the three-day outage.
