CSIDB logo
Incident

Springfield Public Schools

Incident posture

Attack window
Sep 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-09 17:38

Linked entities

Victim
Springfield Public Schools
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2026
Discovered
Sep 2026
Disclosed
Sep 2026
Resolved
Pending

Summary

Springfield Public Schools experienced a severe, level 4 cyber incident that forced school closures for at least two days and could continue longer. Officials detected malicious traffic and activated an incident response plan to identify, contain, eradicate, and restore affected systems. The disruption prevented access to student health records, transportation and food-related information, and email, leading the district to communicate through social media and text messages. Families were asked not to use school laptops because of concerns that malware could spread. City government systems were not affected by the same incident.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Springfield Public Schools first detected malicious traffic on Tuesday, September 1, 2026. District personnel did not notify families until the following Friday. The issue was later described publicly as a major cyber incident and cyber attack. At a Tuesday afternoon press conference reported on September 9, Springfield Mayor Dominic Sarno said the attack had been classified as “level 4,” meaning it was severe. He did not provide details about the specific actions taken by the attacker or the technical nature of the intrusion, stating that the investigation remained ongoing. The incident affected the school department, while Sarno said Springfield city government had not been hit by the same event.

The cyber incident forced Springfield schools to close on Tuesday and Wednesday. Officials said the closures could continue for a longer period because of student safety concerns. The district was unable to access student health records, transportation information, and food-related information. It also could not use email, disrupting a normal communication channel with families and the school community. In place of email, the school department continued communicating through social media posts and text messages. Officials asked students and families not to use school-issued laptops because of concern that doing so could spread the malware.

Springfield School Department Technology Director Robert St. Lawrence said staff initiated a cyber incident response plan once the threat was clear. He described the response as focused first on identifying the threats and then working to contain and eradicate them. According to St. Lawrence, restoration of services would follow after confirmation related to that response work. Superintendent Dr. Sonia Dinnall said teachers were developing workarounds while the computer system remained unavailable. She also said the district’s educators were able to provide instruction without technology. The available information did not identify the attacker, explain how the malicious traffic entered the district’s systems, or state when full services would be restored.

Sources

Sources available to members: 1 source.

CSIDB