South St. Paul Public Schools took systems offline after network intrusion
- Organization
- South St. Paul Public Schools
- Exploit
- Ransomware
- Industry
- Education
South St. Paul Public Schools, a district in the Minneapolis and St. Paul metropolitan area of Minnesota, notified staff and families early in the week of March 4, 2024 that technical difficulties might disrupt online platforms, email and other digital services.
The district said the following day that it had been made aware of unauthorized activity within its computer network. Administrators took systems offline to isolate the problem and engaged a third-party cybersecurity firm to help restore the network and to investigate the cause and scope of the activity. Officials said the priority was restoring services so students and staff could keep working, and acknowledged that cyber threats had become a routine risk for schools.
Neither the district nor its advisers said publicly what data, if any, had been accessed. The St. Paul Pioneer Press reported on March 6 that officials had not responded to questions about the state of the investigation.
Later reporting by The 74, published with WIRED in February 2025, noted that the BlackSuit ransomware group listed South St. Paul Public Schools on its leak site in March 2024. The extent of any data published was never established. The district did not publicly confirm a ransomware attack and did not issue a notification describing what personal information was involved.