CSIDB logo
Incident

Lyon County School District

Incident posture

Attack window
Nov 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-04 00:00

Linked entities

Victim
Lyon County School District
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack encrypted the Lincoln County School District's computer systems, disrupting network operations and impacting phone and internet communications across multiple K-12 schools. The district collaborated with various agencies to investigate the incident while its technology team worked to restore services affected by the network outage.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On November 4, 2019, the Lincoln County School District in Mississippi experienced a significant ransomware attack that disrupted its operations. The district initially reported a network outage affecting phone systems and internet communications across all schools, prompting its technology department to begin remediation efforts. Superintendent Mickey Myers subsequently confirmed the incident was caused by a ransomware virus that had encrypted district computer systems, adversely impacting multiple network components. The attack compromised critical infrastructure, though specific technical details about the ransomware variant or initial attack vector were not publicly disclosed. District administrators engaged with multiple external agencies to investigate the incident, though Myers could not confirm whether the FBI was directly involved despite standard protocols requiring federal notification. FBI spokesperson Brett Carr emphasized the agency’s standard procedure of vetting and investigating such complaints before escalating to appropriate law enforcement entities.

The cyberattack affected all district attendance centers—Bogue Chitto, Loyd Star, Enterprise, and West Lincoln—which collectively served kindergarten through 12th-grade students. While no data theft or student safety risks were explicitly mentioned, the encryption of systems hindered administrative and communication functions district-wide. Superintendent Myers’ written statement emphasized the ongoing collaborative investigation but provided no timeline for full restoration of services. The district’s reliance on compromised systems underscored operational vulnerabilities, particularly in phone and internet-dependent activities. No ransom demands, payment status, or data recovery methods were disclosed in available reports, leaving the long-term resolution unclear as of the last public update.

Sources

Sources available to members: 1 source.

CSIDB