A Network Connecting School Leaders From Around The Globe
The Week the Screens Went Dark
A Fictional—but Highly Possible—Cyberattack on a 3,000-Student School District
by Michael Keany
November 2026
Maple Valley School District serves 3,000 students in a comfortable suburban community: three elementary schools, a middle school, and a high school.
The attack begins with an ordinary email.
A payroll employee receives what appears to be a message from one of the district’s benefits vendors. The message says employees must verify information before open enrollment. She follows the link and enters her district username and password into a convincing imitation website.
Nothing happens.
She closes the window and goes back to work.
But someone else now has her credentials.
Over the following days, the attackers quietly explore the district’s network, searching for accounts, servers, backups, financial records, employee information, and student files. Compromised credentials and sophisticated social engineering are among the initial-access methods specifically identified in federal ransomware guidance. (CISA)
Week 3 — Monday, 5:47 A.M.
The technology director’s phone begins buzzing.
Teachers cannot log in.
The student information system is unavailable. Attendance cannot be entered. Shared drives have disappeared. Payroll files will not open. Some office computers display the same message:
YOUR FILES HAVE BEEN ENCRYPTED.
School opens anyway.
Teachers take attendance on paper. Cafeteria workers use handwritten lists. The transportation office cannot immediately access some routing information. Teachers discover that years of lesson materials stored on district servers are inaccessible.
By noon, administrators shut down much of the network to contain the damage.
That evening, families receive a text:
“Maple Valley Schools has experienced a cybersecurity incident.”
Week 3 — Wednesday
The situation becomes worse.
Investigators determine that the hackers did not simply encrypt files. They apparently copied data before locking the district out—a practice commonly called double extortion. Ransomware groups increasingly threaten to publish stolen data as additional leverage. (CISA)
The stolen information may include student names, addresses, birth dates, disciplinary records, special-education documents, employee tax information, and personnel files.
The attackers demand $1.2 million and threaten to release the information if the district refuses.
The superintendent calls the FBI, the district’s cyber insurer, attorneys, forensic specialists, and state authorities.
School is canceled for two days.
Week 4 — Back to Paper
Classes resume—but technology largely does not.
Teachers use whiteboards, textbooks, photocopies, and handwritten assignments. Office staff rebuild attendance lists. Nurses maintain temporary paper records.
Ironically, instruction continues reasonably well.
Administration does not.
Purchase orders, payroll procedures, special-education documentation, substitute management, student scheduling, and parent communications are enormously more difficult without functioning systems.
Rumors explode on social media.
“Did they steal Social Security numbers?”
“Are children’s medical records online?”
“Did the district pay the ransom?”
The superintendent can answer some questions but not all of them.
Federal research shows why districts fear these incidents: ransomware can disrupt both learning and routine school operations, while recovery can extend for months. (Government Accountability Office)
Week 6 — The Decision
After consultation with law enforcement, insurers, attorneys, and cybersecurity experts, the board meets in executive session.
The district announces the next morning that it will not pay the ransom.
Fortunately, one decision made months earlier now proves critical: the district maintained separate backups that the attackers apparently could not reach.
Recovery begins.
But restoration is slow. Every server and device must be examined before reconnecting it. Passwords are reset. Accounts are rebuilt. Some computers are wiped completely.
CISA recommends offline, encrypted backups precisely because ransomware can attack backups that remain connected to a compromised network. (CISA)
November — The Data Appears
A cybersecurity monitoring company discovers samples of Maple Valley information posted on a criminal leak site.
Affected families and employees receive notification letters. Credit-monitoring services are offered where appropriate.
Anger shifts from the hackers to the district.
Parents ask a harder question:
“How could this have happened?”
January — Almost Normal
Four months after that first fraudulent email, most district systems are operating normally.
The final bill exceeds the ransom demand when forensic consultants, replacement equipment, legal services, notification expenses, security improvements, and staff overtime are counted.
That, too, resembles real incidents. GAO has reported district cyberattack costs ranging from tens of thousands to as much as $1 million in the cases it reviewed. (Government Accountability Office)
June — The Lessons
At year’s end, Maple Valley looks different.
Multifactor authentication is required for staff accounts. Administrative privileges are sharply restricted. Networks are segmented so one compromised account cannot easily reach everything. Backups are isolated and routinely tested. Software is patched more aggressively. Employees receive recurring phishing training.
Most importantly, the district creates and practices a Cyber Incident Response Plan. Administrators conduct tabletop exercises just as they conduct fire and emergency drills.
The biggest lesson is surprisingly simple:
Cybersecurity is no longer merely the technology director’s responsibility.
It is a school safety and continuity-of-learning responsibility.
A 3,000-student district can have excellent teachers, strong principals, modern buildings, and impressive programs—and still discover that one stolen password can threaten the operation of the entire organization.
Five References
——————————
Prepared with the assistance of AI software OpenAI. (2026). ChatGPT (5.2) [Large language model]. https://chat.openai.com ;
SUBSCRIBE TO
SCHOOL LEADERSHIP 2.0
Feedspot named School Leadership 2.0 one of the "Top 25 Educational Leadership Blogs"
"School Leadership 2.0 is the premier virtual learning community for school leaders from around the globe."
---------------------------
Our community is a subscription-based paid service ($19.95/year or only $1.99 per month for a trial membership) that will provide school leaders with outstanding resources. Learn more about membership to this service by clicking one of our links below.
Click HERE to subscribe as an individual.
Click HERE to learn about group membership (i.e., association, leadership teams)
__________________
CREATE AN EMPLOYER PROFILE AND GET JOB ALERTS AT
SCHOOLLEADERSHIPJOBS.COM
Mentors.net - a Professional Development Resource
Mentors.net was founded in 1995 as a professional development resource for school administrators leading new teacher induction programs. It soon evolved into a destination where both new and student teachers could reflect on their teaching experiences. Now, nearly thirty years later, Mentors.net has taken on a new direction—serving as a platform for beginning teachers, preservice educators, and
other professionals to share their insights and experiences from the early years of teaching, with a focus on integrating artificial intelligence. We invite you to contribute by sharing your experiences in the form of a journal article, story, reflection, or timely tips, especially on how you incorporate AI into your teaching
practice. Submissions may range from a 500-word personal reflection to a 2,000-word article with formal citations.
You need to be a member of School Leadership 2.0 to add comments!
Join School Leadership 2.0