CSIDB logo
Incident

Lyon County School District

Incident posture

Attack window
Jul 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-03 00:00

Linked entities

Victim
Lyon County School District
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Lyon County school district experienced a cyber attack involving a virus that infiltrated its network, causing widespread system outages and disrupting phone services and other network-dependent operations. The incident necessitated extensive restoration efforts to recover affected infrastructure, with the district actively working to resolve the compromise and restore normal functionality across its services.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Lyon County School District experienced a cyber attack in early July 2019 that disrupted critical operations across its network. A malicious virus infiltrated the district's systems around July 8, causing widespread technical outages that persisted for multiple days. The attack disabled core IT infrastructure, rendering essential services inoperable. Superintendent Wayne Workman publicly confirmed the incident on July 15 while restoration efforts were underway. Network-connected phone systems became completely nonfunctional during the outage, severely hampering internal and external communications. The district's administrative and educational technology systems were simultaneously compromised, though specific affected applications weren't detailed in public reports. This disruption occurred during summer operations when many staff members were preparing for the upcoming academic year.

District technicians immediately initiated containment protocols upon detecting the virus, though the exact timeline between infection discovery and public disclosure remains unspecified. Recovery operations focused on system restoration rather than forensic analysis in the initial response phase. Workman's confirmation came one week after the attack began, indicating ongoing technical challenges. The incident marked another entry in a series of cyber attacks targeting Northern Nevada public agencies that summer, though no attribution or connection to other attacks was established. Restoration priorities included reactivating communication systems and securing core educational platforms before the start of the fall semester.

Sources

Sources available to members: 1 source.

CSIDB