The Week the Screens Went Dark A Fictional (but Highly Possible) Cyberattack on a Suburban School District

The Week the Screens Went Dark

A Fictional—but Highly Possible—Cyberattack on a 3,000-Student School District

by Michael Keany

November 2026


September — The Door Opens

Maple Valley School District serves 3,000 students in a comfortable suburban community: three elementary schools, a middle school, and a high school.

The attack begins with an ordinary email.

A payroll employee receives what appears to be a message from one of the district’s benefits vendors. The message says employees must verify information before open enrollment. She follows the link and enters her district username and password into a convincing imitation website.

Nothing happens.

She closes the window and goes back to work.

But someone else now has her credentials.

Over the following days, the attackers quietly explore the district’s network, searching for accounts, servers, backups, financial records, employee information, and student files. Compromised credentials and sophisticated social engineering are among the initial-access methods specifically identified in federal ransomware guidance. (CISA)

Week 3 — Monday, 5:47 A.M.

The technology director’s phone begins buzzing.

Teachers cannot log in.

The student information system is unavailable. Attendance cannot be entered. Shared drives have disappeared. Payroll files will not open. Some office computers display the same message:

YOUR FILES HAVE BEEN ENCRYPTED.

School opens anyway.

Teachers take attendance on paper. Cafeteria workers use handwritten lists. The transportation office cannot immediately access some routing information. Teachers discover that years of lesson materials stored on district servers are inaccessible.

By noon, administrators shut down much of the network to contain the damage.

That evening, families receive a text:

“Maple Valley Schools has experienced a cybersecurity incident.”

Week 3 — Wednesday

The situation becomes worse.

Investigators determine that the hackers did not simply encrypt files. They apparently copied data before locking the district out—a practice commonly called double extortion. Ransomware groups increasingly threaten to publish stolen data as additional leverage. (CISA)

The stolen information may include student names, addresses, birth dates, disciplinary records, special-education documents, employee tax information, and personnel files.

The attackers demand $1.2 million and threaten to release the information if the district refuses.

The superintendent calls the FBI, the district’s cyber insurer, attorneys, forensic specialists, and state authorities.

School is canceled for two days.

Week 4 — Back to Paper

Classes resume—but technology largely does not.

Teachers use whiteboards, textbooks, photocopies, and handwritten assignments. Office staff rebuild attendance lists. Nurses maintain temporary paper records.

Ironically, instruction continues reasonably well.

Administration does not.

Purchase orders, payroll procedures, special-education documentation, substitute management, student scheduling, and parent communications are enormously more difficult without functioning systems.

Rumors explode on social media.

“Did they steal Social Security numbers?”

“Are children’s medical records online?”

“Did the district pay the ransom?”

The superintendent can answer some questions but not all of them.

Federal research shows why districts fear these incidents: ransomware can disrupt both learning and routine school operations, while recovery can extend for months. (Government Accountability Office)

Week 6 — The Decision

After consultation with law enforcement, insurers, attorneys, and cybersecurity experts, the board meets in executive session.

The district announces the next morning that it will not pay the ransom.

Fortunately, one decision made months earlier now proves critical: the district maintained separate backups that the attackers apparently could not reach.

Recovery begins.

But restoration is slow. Every server and device must be examined before reconnecting it. Passwords are reset. Accounts are rebuilt. Some computers are wiped completely.

CISA recommends offline, encrypted backups precisely because ransomware can attack backups that remain connected to a compromised network. (CISA)

November — The Data Appears

A cybersecurity monitoring company discovers samples of Maple Valley information posted on a criminal leak site.

Affected families and employees receive notification letters. Credit-monitoring services are offered where appropriate.

Anger shifts from the hackers to the district.

Parents ask a harder question:

“How could this have happened?”

January — Almost Normal

Four months after that first fraudulent email, most district systems are operating normally.

The final bill exceeds the ransom demand when forensic consultants, replacement equipment, legal services, notification expenses, security improvements, and staff overtime are counted.

That, too, resembles real incidents. GAO has reported district cyberattack costs ranging from tens of thousands to as much as $1 million in the cases it reviewed. (Government Accountability Office)

June — The Lessons

At year’s end, Maple Valley looks different.

Multifactor authentication is required for staff accounts. Administrative privileges are sharply restricted. Networks are segmented so one compromised account cannot easily reach everything. Backups are isolated and routinely tested. Software is patched more aggressively. Employees receive recurring phishing training.

Most importantly, the district creates and practices a Cyber Incident Response Plan. Administrators conduct tabletop exercises just as they conduct fire and emergency drills.

The biggest lesson is surprisingly simple:

Cybersecurity is no longer merely the technology director’s responsibility.

It is a school safety and continuity-of-learning responsibility.

A 3,000-student district can have excellent teachers, strong principals, modern buildings, and impressive programs—and still discover that one stolen password can threaten the operation of the entire organization.

Five References

  1. Cybersecurity and Infrastructure Security Agency (CISA). #StopRansomware Guide. Guidance recommends phishing-resistant multifactor authentication, network segmentation, offline encrypted backups, incident-response planning, logging, and tested recovery procedures. (CISA)
  2. U.S. Government Accountability Office. Critical Infrastructure Protection: Additional Federal Coordination Is Needed to Enhance K–12 Cybersecurity. GAO-23-105480, October 2022. Documents instructional downtime and lengthy recovery periods following K–12 cyber incidents. (Government Accountability Office)
  3. U.S. Department of Education, Readiness and Emergency Management for Schools Technical Assistance Center. Ransomware Attacks and the Importance of Collaboration in District-Level Cybersecurity Risk Management, 2024. Discusses prevention, response, recovery, and collaboration during school ransomware incidents. (U.S. Department of Education)
  4. CISA, FBI, and Australian Signals Directorate’s Australian Cyber Security Centre. #StopRansomware: Play Ransomware, updated June 2025. Describes modern double-extortion attacks involving both data theft and encryption and recommends MFA, backups, patching, and recovery planning. (CISA)
  5. U.S. Department of Education. Cybersecurity for K–12 Schools and School Districts: Developing a Cyber Annex. Recommends assessing infrastructure and vulnerabilities, coordinating with cybersecurity partners, incorporating cyber incidents into emergency operations plans, and regularly exercising those plans. (U.S. Department of Education)

——————————

Prepared with the assistance of AI software OpenAI. (2026). ChatGPT (5.2) [Large language model]. https://chat.openai.com ;

Views: 17

Comment

You need to be a member of School Leadership 2.0 to add comments!

Join School Leadership 2.0

JOIN SL 2.0

SUBSCRIBE TO

SCHOOL LEADERSHIP 2.0

Feedspot named School Leadership 2.0 one of the "Top 25 Educational Leadership Blogs"

"School Leadership 2.0 is the premier virtual learning community for school leaders from around the globe."

---------------------------

 Our community is a subscription-based paid service ($19.95/year or only $1.99 per month for a trial membership)  that will provide school leaders with outstanding resources. Learn more about membership to this service by clicking one of our links below.

 

Click HERE to subscribe as an individual.

 

Click HERE to learn about group membership (i.e., association, leadership teams)

__________________

CREATE AN EMPLOYER PROFILE AND GET JOB ALERTS AT 

SCHOOLLEADERSHIPJOBS.COM

New Partnership

Mentors.net - a Professional Development Resource

Mentors.net was founded in 1995 as a professional development resource for school administrators leading new teacher induction programs. It soon evolved into a destination where both new and student teachers could reflect on their teaching experiences. Now, nearly thirty years later, Mentors.net has taken on a new direction—serving as a platform for beginning teachers, preservice educators, and

other professionals to share their insights and experiences from the early years of teaching, with a focus on integrating artificial intelligence. We invite you to contribute by sharing your experiences in the form of a journal article, story, reflection, or timely tips, especially on how you incorporate AI into your teaching

practice. Submissions may range from a 500-word personal reflection to a 2,000-word article with formal citations.

© 2026   Created by William Brennan and Michael Keany   Powered by

Badges  |  Report an Issue  |  Terms of Service