A Fictional—but Highly Possible—Cyberattack on a 3,000-Student School District
by Michael Keany
November 2026
September — The Door Opens
Maple Valley School District serves 3,000 students in a comfortable suburban community: three elementary schools, a middle school, and a high school.
The attack begins with an ordinary email.
A payroll employee receives what appears to be a message from one of the district’s benefits vendors. The message says employees must verify information before open enrollment. She follows the link and enters her district username and password into a convincing imitation website.
Nothing happens.
She closes the window and goes back to work.
But someone else now has her credentials.
Over the following days, the attackers quietly explore the district’s network, searching for accounts, servers, backups, financial records, employee information, and student files. Compromised credentials and sophisticated social engineering are among the initial-access methods specifically identified in federal ransomware guidance. (CISA)
Week 3 — Monday, 5:47 A.M.
The technology director’s phone begins buzzing.
Teachers cannot log in.
The student information system is unavailable. Attendance cannot be entered. Shared drives have disappeared. Payroll files will not open. Some office computers display the same message:
YOUR FILES HAVE BEEN ENCRYPTED.
School opens anyway.
Teachers take attendance on paper. Cafeteria workers use handwritten lists. The transportation office cannot immediately access some routing information. Teachers discover that years of lesson materials stored on district servers are inaccessible.
By noon, administrators shut down much of the network to contain the damage.
That evening, families receive a text:
“Maple Valley Schools has experienced a cybersecurity incident.”
Week 3 — Wednesday
The situation becomes worse.
Investigators determine that the hackers did not simply encrypt files. They apparentlycopied data before locking the district out—a practice commonly called double extortion. Ransomware groups increasingly threaten to publish stolen data as additional leverage. (CISA)
The stolen information may include student names, addresses, birth dates, disciplinary records, special-education documents, employee tax information, and personnel files.
The attackers demand$1.2 millionand threaten to release the information if the district refuses.
The superintendent calls the FBI, the district’s cyber insurer, attorneys, forensic specialists, and state authorities.
School is canceled for two days.
Week 4 — Back to Paper
Classes resume—but technology largely does not.
Teachers use whiteboards, textbooks, photocopies, and handwritten assignments. Office staff rebuild attendance lists. Nurses maintain temporary paper records.
Purchase orders, payroll procedures, special-education documentation, substitute management, student scheduling, and parent communications are enormously more difficult without functioning systems.
Rumors explode on social media.
“Did they steal Social Security numbers?”
“Are children’s medical records online?”
“Did the district pay the ransom?”
The superintendent can answer some questions but not all of them.
Federal research shows why districts fear these incidents: ransomware can disrupt both learning and routine school operations, while recovery can extend for months. (Government Accountability Office)
Week 6 — The Decision
After consultation with law enforcement, insurers, attorneys, and cybersecurity experts, the board meets in executive session.
The district announces the next morning that itwill not pay the ransom.
Fortunately, one decision made months earlier now proves critical: the district maintained separate backups that the attackers apparently could not reach.
Recovery begins.
But restoration is slow. Every server and device must be examined before reconnecting it. Passwords are reset. Accounts are rebuilt. Some computers are wiped completely.
CISA recommends offline, encrypted backups precisely because ransomware can attack backups that remain connected to a compromised network. (CISA)
November — The Data Appears
A cybersecurity monitoring company discovers samples of Maple Valley information posted on a criminal leak site.
Affected families and employees receive notification letters. Credit-monitoring services are offered where appropriate.
Anger shifts from the hackers to the district.
Parents ask a harder question:
“How could this have happened?”
January — Almost Normal
Four months after that first fraudulent email, most district systems are operating normally.
The final bill exceeds the ransom demand when forensic consultants, replacement equipment, legal services, notification expenses, security improvements, and staff overtime are counted.
That, too, resembles real incidents. GAO has reported district cyberattack costs ranging from tens of thousands to as much as $1 million in the cases it reviewed. (Government Accountability Office)
June — The Lessons
At year’s end, Maple Valley looks different.
Multifactor authentication is required for staff accounts. Administrative privileges are sharply restricted. Networks are segmented so one compromised account cannot easily reach everything. Backups are isolated and routinely tested. Software is patched more aggressively. Employees receive recurring phishing training.
Most importantly, the district creates and practices aCyber Incident Response Plan. Administrators conduct tabletop exercises just as they conduct fire and emergency drills.
The biggest lesson is surprisingly simple:
Cybersecurity is no longer merely the technology director’s responsibility.
It is aschool safety and continuity-of-learning responsibility.
A 3,000-student district can have excellent teachers, strong principals, modern buildings, and impressive programs—and still discover that one stolen password can threaten the operation of the entire organization.
U.S. Government Accountability Office.Critical Infrastructure Protection: Additional Federal Coordination Is Needed to Enhance K–12 Cybersecurity.GAO-23-105480, October 2022. Documents instructional downtime and lengthy recovery periods following K–12 cyber incidents. (Government Accountability Office)
U.S. Department of Education, Readiness and Emergency Management for Schools Technical Assistance Center.Ransomware Attacks and the Importance of Collaboration in District-Level Cybersecurity Risk Management, 2024. Discusses prevention, response, recovery, and collaboration during school ransomware incidents. (U.S. Department of Education)
CISA, FBI, and Australian Signals Directorate’s Australian Cyber Security Centre.#StopRansomware: Play Ransomware, updated June 2025. Describes modern double-extortion attacks involving both data theft and encryption and recommends MFA, backups, patching, and recovery planning. (CISA)
U.S. Department of Education.Cybersecurity for K–12 Schools and School Districts: Developing a Cyber Annex.Recommends assessing infrastructure and vulnerabilities, coordinating with cybersecurity partners, incorporating cyber incidents into emergency operations plans, and regularly exercising those plans. (U.S. Department of Education)
——————————
Prepared with the assistance of AI software OpenAI. (2026). ChatGPT (5.2) [Large language model]. https://chat.openai.com ;
The Week the Screens Went Dark A Fictional (but Highly Possible) Cyberattack on a Suburban School District
by Michael Keany
yesterday
The Week the Screens Went Dark
A Fictional—but Highly Possible—Cyberattack on a 3,000-Student School District
by Michael Keany
November 2026
September — The Door Opens
Maple Valley School District serves 3,000 students in a comfortable suburban community: three elementary schools, a middle school, and a high school.
The attack begins with an ordinary email.
A payroll employee receives what appears to be a message from one of the district’s benefits vendors. The message says employees must verify information before open enrollment. She follows the link and enters her district username and password into a convincing imitation website.
Nothing happens.
She closes the window and goes back to work.
But someone else now has her credentials.
Over the following days, the attackers quietly explore the district’s network, searching for accounts, servers, backups, financial records, employee information, and student files. Compromised credentials and sophisticated social engineering are among the initial-access methods specifically identified in federal ransomware guidance. (CISA)
Week 3 — Monday, 5:47 A.M.
The technology director’s phone begins buzzing.
Teachers cannot log in.
The student information system is unavailable. Attendance cannot be entered. Shared drives have disappeared. Payroll files will not open. Some office computers display the same message:
YOUR FILES HAVE BEEN ENCRYPTED.
School opens anyway.
Teachers take attendance on paper. Cafeteria workers use handwritten lists. The transportation office cannot immediately access some routing information. Teachers discover that years of lesson materials stored on district servers are inaccessible.
By noon, administrators shut down much of the network to contain the damage.
That evening, families receive a text:
“Maple Valley Schools has experienced a cybersecurity incident.”
Week 3 — Wednesday
The situation becomes worse.
Investigators determine that the hackers did not simply encrypt files. They apparently copied data before locking the district out—a practice commonly called double extortion. Ransomware groups increasingly threaten to publish stolen data as additional leverage. (CISA)
The stolen information may include student names, addresses, birth dates, disciplinary records, special-education documents, employee tax information, and personnel files.
The attackers demand $1.2 million and threaten to release the information if the district refuses.
The superintendent calls the FBI, the district’s cyber insurer, attorneys, forensic specialists, and state authorities.
School is canceled for two days.
Week 4 — Back to Paper
Classes resume—but technology largely does not.
Teachers use whiteboards, textbooks, photocopies, and handwritten assignments. Office staff rebuild attendance lists. Nurses maintain temporary paper records.
Ironically, instruction continues reasonably well.
Administration does not.
Purchase orders, payroll procedures, special-education documentation, substitute management, student scheduling, and parent communications are enormously more difficult without functioning systems.
Rumors explode on social media.
“Did they steal Social Security numbers?”
“Are children’s medical records online?”
“Did the district pay the ransom?”
The superintendent can answer some questions but not all of them.
Federal research shows why districts fear these incidents: ransomware can disrupt both learning and routine school operations, while recovery can extend for months. (Government Accountability Office)
Week 6 — The Decision
After consultation with law enforcement, insurers, attorneys, and cybersecurity experts, the board meets in executive session.
The district announces the next morning that it will not pay the ransom.
Fortunately, one decision made months earlier now proves critical: the district maintained separate backups that the attackers apparently could not reach.
Recovery begins.
But restoration is slow. Every server and device must be examined before reconnecting it. Passwords are reset. Accounts are rebuilt. Some computers are wiped completely.
CISA recommends offline, encrypted backups precisely because ransomware can attack backups that remain connected to a compromised network. (CISA)
November — The Data Appears
A cybersecurity monitoring company discovers samples of Maple Valley information posted on a criminal leak site.
Affected families and employees receive notification letters. Credit-monitoring services are offered where appropriate.
Anger shifts from the hackers to the district.
Parents ask a harder question:
“How could this have happened?”
January — Almost Normal
Four months after that first fraudulent email, most district systems are operating normally.
The final bill exceeds the ransom demand when forensic consultants, replacement equipment, legal services, notification expenses, security improvements, and staff overtime are counted.
That, too, resembles real incidents. GAO has reported district cyberattack costs ranging from tens of thousands to as much as $1 million in the cases it reviewed. (Government Accountability Office)
June — The Lessons
At year’s end, Maple Valley looks different.
Multifactor authentication is required for staff accounts. Administrative privileges are sharply restricted. Networks are segmented so one compromised account cannot easily reach everything. Backups are isolated and routinely tested. Software is patched more aggressively. Employees receive recurring phishing training.
Most importantly, the district creates and practices a Cyber Incident Response Plan. Administrators conduct tabletop exercises just as they conduct fire and emergency drills.
The biggest lesson is surprisingly simple:
Cybersecurity is no longer merely the technology director’s responsibility.
It is a school safety and continuity-of-learning responsibility.
A 3,000-student district can have excellent teachers, strong principals, modern buildings, and impressive programs—and still discover that one stolen password can threaten the operation of the entire organization.
Five References
——————————
Prepared with the assistance of AI software OpenAI. (2026). ChatGPT (5.2) [Large language model]. https://chat.openai.com ;