CSIDB logo
Incident

Pickens County School District

Incident posture

Attack window
Feb 2016
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-11 00:00

Linked entities

Victim
Pickens County School District
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hackers repeatedly overloaded a school district's computer network using robotic systems, severely limiting internet access for employees over multiple weeks. The district's website also crashed due to unrelated Microsoft software issues, though no data breach occurred. These disruptions coincided with AT&T infrastructure complications and affected multiple educational systems across the state. District officials confirmed the cyberattacks aimed to force network shutdowns while addressing separate technical failures that temporarily disabled public-facing services.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In mid-February 2016, Pickens County School District experienced repeated network disruptions caused by external attackers targeting its internet infrastructure. Hackers deployed robotic systems to overload the district's network through volumetric attacks, significantly degrading internet accessibility for district employees over multiple weeks. These incidents coincided with broader cyber targeting of several South Carolina school districts. On February 26, the district's Microsoft-based website (www.pickens.k12.sc.us) crashed entirely during morning operations due to unrelated software failures within Microsoft's systems, compounding existing network instability. District spokesman John Eby publicly confirmed the dual challenges of sustained malicious traffic and third-party technical failures, noting AT&T service complications further exacerbated network reliability. The disruptions occurred during a period of heightened community tensions regarding proposed school closures and potential tax increases for facility improvements.

District technicians restored website functionality by noon on February 26 after Microsoft resolved the underlying software issue. Officials emphasized no evidence suggested data breaches or unauthorized access to sensitive information throughout the incidents. The sustained network overload attacks prompted administrative discussions about countermeasures, with Assistant Superintendent Bill Roach proposing financial rewards for information leading to hacker identification during a district meeting. Operational impacts remained confined to internet accessibility issues rather than compromised data integrity, though the disruptions hindered administrative functions during critical budget deliberations. Technical staff continued monitoring network traffic patterns while maintaining public assurances about system security fundamentals despite the availability challenges.

Sources

Sources available to members: 1 source.

CSIDB