Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Badges, Bytes and Blackmail

February 7, 2026

Ex-Google Engineer Convicted for Stealing AI Secrets for China Startup

February 7, 2026

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026
Facebook X (Twitter) Instagram
Saturday, February 7
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Qilin Claims Ransomware Attack on Mecklenburg Schools
News

Qilin Claims Ransomware Attack on Mecklenburg Schools

Team-CWDBy Team-CWDOctober 8, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A ransomware attack that disrupted operations at Mecklenburg County Public Schools (MCPS) in early September has been claimed by the Russian cybercrime group Qilin.

The gang said it stole 305 GB of sensitive data from the southern Virginia district, including financial records, grant documents, budgets and children’s medical files.

Cyber-Attack Shuts Down Schools

MCPS first alerted families to a cybersecurity incident on September 2 2025. The attack forced teachers offline, leaving them relying on pen, paper and whiteboards for instruction. Internet systems were restored about a week later.

Qilin later published sample images online, which it claimed were part of the stolen files. Superintendent Scott Worner confirmed that the group was behind the attack but stated that the school district is still assessing the extent of the breach.

“We don’t intend to move forward with payment at this time,” Worner said.

“The final decision depends on the findings of the investigation and what files were encrypted and/or stolen.”

He also urged other districts to prepare for cyber-threats.

“It’s not if. It’s when,” he said.

“Whoever your insurance company is, make sure your cybersecurity coverage is up to date.”

Qilin’s Expanding Ransomware Reach

Qilin is a ransomware operation that surfaced in late 2022 and runs as a ransomware-as-a-service network. Affiliates use its malware to launch attacks and share ransom proceeds. The group primarily spreads its malware through phishing emails.

So far in 2025, Qilin has claimed responsibility for 103 confirmed ransomware incidents and 470 unverified ones. Educational institutions have been frequent targets.

Other victims this year include:

  • Western New Mexico University

  • Botetourt County Public Schools in Virginia

  • Fort Smith Public Schools in Arkansas

  • Belmont Christian College in Australia

Read more on ransomware threats to schools: ICO Warns of Student-Led Data Breaches in UK Schools

Rising Impact on Education

Data from Comparitech shows at least 33 confirmed ransomware attacks on American schools, colleges and universities in 2025, with another 62 claimed but unverified.

In September alone, districts in Texas and Arizona disclosed new incidents.

The education sector faces unique challenges in responding to breaches, taking an average of 4.8 months to notify affected individuals.

These attacks often cripple essential operations, from attendance and grading to payroll and communication systems, while exposing staff and students to potential identity fraud.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCISA Sounds Alarm on Critical Sudo Flaw Actively Exploited in Linux and Unix Systems
Next Article U.K. Police Just Seized £5.5 Billion in Bitcoin — The World’s Largest Crypto Bust
Team-CWD
  • Website

Related Posts

News

Badges, Bytes and Blackmail

February 7, 2026
News

Ex-Google Engineer Convicted for Stealing AI Secrets for China Startup

February 7, 2026
News

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

Find your weak spots before attackers do

November 21, 2025

Children and chatbots: What parents should know

January 23, 2026

What it is and how to protect yourself

January 8, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.