CSIDB logo
Incident

San Dieguito Union High School District

Incident posture

Attack window
Aug 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-03 00:00

Linked entities

Victim
San Dieguito Union High School District
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Aug 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A North County school district experienced a malware attack that disrupted network operations during a critical registration period, prompting a partial shutdown of their systems. The district notified parents of the incident, initially describing it as an attempted attack but later confirming malware had been successfully inserted into their network. This caused significant operational interference during a high-demand administrative timeframe.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On August 9, 2019, San Dieguito Union High School District in California experienced a malware attack that compromised its network systems. The district characterized the event as an "attempted malware attack" in communications to parents but external reporting confirmed malicious software was successfully inserted into the network. The incident occurred during registration week, a critical operational period for the district. In response to the attack, administrators shut down affected portions of the network infrastructure to contain the threat and prevent further spread of the malware. This disruption impacted normal district operations during a high-activity enrollment period, though specific affected systems or services were not detailed in public disclosures.

The district notified parents of the cybersecurity incident via email on August 15, 2019—six days after initial detection—providing confirmation of the malware attack but no specifics regarding data compromise or operational damage. Network segments remained offline during containment efforts, with no public timeline provided for full restoration. External cybersecurity analysts emphasized the attack exceeded the district's description of an "attempt," confirming actual malware implantation. No threat actor attribution, ransom demands, or data exfiltration claims were disclosed in available reporting. The incident highlighted operational vulnerabilities during peak administrative periods, though long-term consequences or remediation costs were not formally documented in public sources.

Sources

Sources available to members: 1 source.

CSIDB