Springfield Public Schools
Incident posture
Linked entities
- Victim
- Springfield Public Schools
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Springfield Public Schools experienced a severe, level 4 cyber incident that forced school closures for at least two days and could continue longer. Officials detected malicious traffic and activated an incident response plan to identify, contain, eradicate, and restore affected systems. The disruption prevented access to student health records, transportation and food-related information, and email, leading the district to communicate through social media and text messages. Families were asked not to use school laptops because of concerns that malware could spread. City government systems were not affected by the same incident.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Springfield Public Schools first detected malicious traffic on Tuesday, September 1, 2026. District personnel did not notify families until the following Friday. The issue was later described publicly as a major cyber incident and cyber attack. At a Tuesday afternoon press conference reported on September 9, Springfield Mayor Dominic Sarno said the attack had been classified as “level 4,” meaning it was severe. He did not provide details about the specific actions taken by the attacker or the technical nature of the intrusion, stating that the investigation remained ongoing. The incident affected the school department, while Sarno said Springfield city government had not been hit by the same event.
The cyber incident forced Springfield schools to close on Tuesday and Wednesday. Officials said the closures could continue for a longer period because of student safety concerns. The district was unable to access student health records, transportation information, and food-related information. It also could not use email, disrupting a normal communication channel with families and the school community. In place of email, the school department continued communicating through social media posts and text messages. Officials asked students and families not to use school-issued laptops because of concern that doing so could spread the malware.
Springfield School Department Technology Director Robert St. Lawrence said staff initiated a cyber incident response plan once the threat was clear. He described the response as focused first on identifying the threats and then working to contain and eradicate them. According to St. Lawrence, restoration of services would follow after confirmation related to that response work. Superintendent Dr. Sonia Dinnall said teachers were developing workarounds while the computer system remained unavailable. She also said the district’s educators were able to provide instruction without technology. The available information did not identify the attacker, explain how the malicious traffic entered the district’s systems, or state when full services would be restored.
Sources
Sources available to members: 1 source.