Cyber Incident Victim: Lyon County School District
Date:
Nov 2019
Location:
United States of America
Summary
A ransomware attack encrypted the Lincoln County School District's computer systems, disrupting network operations and impacting phone and internet communications across multiple K-12 schools. The district collaborated with various agencies to investigate the incident while its technology team worked to restore services affected by the network outage.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On November 4, 2019, the Lincoln County School District in Mississippi experienced a significant ransomware attack that disrupted its operations. The district initially reported a network outage affecting phone systems and internet communications across all schools, prompting its technology department to begin remediation efforts. Superintendent Mickey Myers subsequently confirmed the incident was caused by a ransomware virus that had encrypted district computer systems, adversely impacting multiple network components. The attack compromised critical infrastructure, though specific technical details about the ransomware variant or initial attack vector were not publicly disclosed. District administrators engaged with multiple external agencies to investigate the incident, though Myers could not confirm whether the FBI was directly involved despite standard protocols requiring federal notification. FBI spokesperson Brett Carr emphasized the agency’s standard procedure of vetting and investigating such complaints before escalating to appropriate law enforcement entities.

The cyberattack affected all district attendance centers—Bogue Chitto, Loyd Star, Enterprise, and West Lincoln—which collectively served kindergarten through 12th-grade students. While no data theft or student safety risks were explicitly mentioned, the encryption of systems hindered administrative and communication functions district-wide. Superintendent Myers’ written statement emphasized the ongoing collaborative investigation but provided no timeline for full restoration of services. The district’s reliance on compromised systems underscored operational vulnerabilities, particularly in phone and internet-dependent activities. No ransom demands, payment status, or data recovery methods were disclosed in available reports, leaving the long-term resolution unclear as of the last public update.
