Skip To Main Content
◇ Official District Notice

Technology Services Update:Cybersecurity Incident

Onslow County Schools is responding to a criminal cyberattack that has disrupted our technology infrastructure. Our staff, in coordination with local, state, and federal authorities, is working urgently to restore full services.

▣ Incident Detected: June 9, 2026 ◷ Updated: June 23, 2026 ♢ Investigation Active
This page will be updated as new information becomes available. Last Updated: June 23, 2026.
Technology Systems
Restoration Underway
Response Team
Active — Multi-Agency
Investigation
JCTF — Active
What Happened

OCS Was the Target of a Criminal Cyberattack

In the early morning hours of Tuesday, June 9, 2026, Onslow County Schools detected unauthorized criminal activity within our technology infrastructure. Upon confirmation, district technology staff immediately began taking protective action and notified law enforcement and state cybersecurity authorities.

This was a criminal act carried out by a sophisticated threat actor — not a failure caused by OCS staff, students, or any member of our community. OCS was not singled out. This group has conducted similar attacks against schools, hospitals, and government agencies across the country and around the world. The education sector has seen a dramatic and well-documented rise in this type of criminal activity in recent years, and OCS, like many districts, became a victim of these bad actors.

It is clear that the swift actions of our IT staff significantly limited both the amount of time the attackers were in our system and the extent of the potential damage. We believe that a relatively small portion of our overall data was exfiltrated, meaning it was copied or taken from our network. While we cannot rule out the possibility that personal student or staff information was accessed, the activity we have been able to trace appears to have been concentrated in areas not associated with sensitive personal data.

A Nationwide Problem
Attacks on K–12 school districts have risen sharply in recent years. Cybercriminals specifically target school systems because of the scale of data they hold and the critical services they provide to communities. OCS is one of hundreds of districts nationwide that have faced this type of criminal intrusion — and, like others before us, we will recover stronger.

Impact & Scope

What Has Been Affected

The criminal activity has impacted our core technology infrastructure — including servers, network systems, and a wide range of digital services used daily across our 42+ school sites. The disruption is broad and has touched systems used by staff, students, and the district's administrative operations.

Regarding Personal Information
The investigation remains ongoing. We continue to work closely with law enforcement and cybersecurity experts to determine the scope of the incident, including whether any personally identifiable information of students or employees was involved. If it is determined that personal information was affected, we will promptly notify impacted individuals in accordance with North Carolina law and our responsibilities to our school community.

Cybercriminals

Important Notice About Potential Contact

Those claiming responsibility for this cyberattack are known for using financial extortion tactics. While we have no indication that any outreach to others outside OCS leadership will occur, there has been a growing trend in similar cases for cybercriminals to attempt to contact staff, families, or other community members in an effort to increase pressure on school districts or organizations when financial extortion attempts have not been successful.

Response to Suspicious Contact
In the unlikely event that you are contacted, law enforcement advises that you do not engage. Please retain any available details about the communication and report it to local authorities. We also ask that you notify our team at tech.support@onslow.k12.nc.us if you receive a message or call that you believe may be connected to this incident.

Our Response

Where We Stand Today

From the moment the attack was detected, OCS technology staff acted quickly to protect our systems and engaged local, state, and federal partners. Our response has been a true team effort, and significant work has already been accomplished.

  • Incident Detected & ContainedAffected systems were isolated to prevent further spread. Criminal activity was stopped.
  • Authorities Notified & Task Force EngagedOCS immediately engaged the NC Joint Cybersecurity Task Force (JCTF) — a coordinated statewide cybersecurity partnership that includes the NC Department of Information Technology (NCDIT), NC Emergency Management (NCEM), the NC National Guard (NCNG), and the NCLGISA IT Strike Team, along with representatives from the Federal Bureau of Investigation and the U.S Secret Service.  OCS also continues to work closely with the North Carolina Department of Public Instruction (NCDPI), MCNC, and the Onslow County Sheriff's Office throughout the response. All required state and federal reporting obligations were fulfilled.
  • Forensic Investigation CompletedThe forensic investigation was conducted by the NC Joint Cybersecurity Task Force (JCTF), the NCLGISA IT Strike Team, the NC National Guard Cyber Security Response Force, NCDIT, and federal law enforcement partners. A comprehensive forensic examination of affected systems has been completed, and the investigation has transitioned into the recovery and restoration phase.
  • Infrastructure Restoration — In ProgressWe are now in the active phase of rebuilding our technology infrastructure. This includes restoring servers, network systems, and digital services. This is a significant undertaking, and while much work remains, substantial progress has already been made.
  • Full Service RestorationSystems will be brought back online in a carefully staged process to ensure security and stability. Timelines will be shared as they are confirmed.
Significant Progress Has Already Been Made
Our team — with the support of state and federal partners — has worked tirelessly since the morning of June 9th. While we cannot share specific technical details while the investigation remains open, we want families and staff to know that real progress is being made every day toward a full restoration of services.

Our Commitment

What You Can Expect From OCS

We understand that disruptions to technology affect every part of our school community — teachers, students, and families alike. We are committed to keeping you informed as our response progresses.

Further updates will be released consistent with guidance from the law enforcement and cybersecurity authorities directing the investigation. We appreciate your patience as we follow that guidance carefully, to protect the integrity of the ongoing investigation.

This page will remain active and will be updated as new information is cleared for public release. Bookmark it and check back regularly.


Resources

Steps You Can Take to Protect Your Personal Information

Regardless of this incident, it is always important to make use of available resources to protect your personal, educational, financial, and medical information, including sensitive data such as your Social Security number. These resources include credit monitoring services and protections available through the IRS. We encourage everyone to remain vigilant by regularly reviewing account statements and monitoring free credit reports.

!

Bank Notifications

Work with your bank or financial institution to enable account and transaction alerts delivered by text, email, or mobile app. These real-time notifications can help you quickly identify suspicious purchases, withdrawals, or unusual activity.

It is generally advisable to limit the use of debit cards for everyday transactions and exercise caution when using paper checks, as both can expose sensitive banking details — such as routing and account numbers — if compromised.

Free Credit Report

You may obtain a free copy of your credit report once every 12 months from each of the three nationwide credit reporting agencies.

The three major bureaus:

  • Equifax: PO Box 740241, Atlanta, GA 30374 • equifax.com • 1-800-685-1111
  • Experian: PO Box 2104, Allen, TX 75013 • experian.com • 1-888-397-3742
  • TransUnion: PO Box 2000, Chester, PA 19022 • transunion.com • 1-833-799-5355
!

Fraud Alert

You may place a fraud alert in your file by contacting any one of the three nationwide credit reporting agencies listed above. A fraud alert tells creditors to follow certain procedures — including contacting you — before opening any new accounts or changing your existing accounts. Placing a fraud alert can protect you, but may also cause a delay when you seek to obtain credit.

🔒

Security Freeze

You may obtain a free security freeze on your credit report to help ensure that credit is not granted in your name without your knowledge. A security freeze prohibits a consumer reporting agency from releasing information in your credit report without your express authorization.

When you place a security freeze, you will be provided with a personal identification number or password to use if you choose to lift or temporarily remove the freeze. To request a freeze, you may use an online process, automated telephone line, or written request to any of the three credit reporting agencies above. You will need to provide: full name, Social Security number, date of birth, current and prior addresses (past 5 years), a copy of a government-issued ID, and a recent utility bill, bank, or insurance statement.

IRS

IRS Identity Protection PIN

An IRS Identity Protection PIN (IP PIN) is a six-digit number that prevents someone else from filing a federal tax return using your Social Security number. A new PIN is issued each year and must be included when you submit your federal return.

The fastest way to get one is through the "Get an IP PIN" tool in your IRS online account at irs.gov. If you cannot complete the online process, you may apply by submitting IRS Form 15227 by mail or visiting an IRS Taxpayer Assistance Center in person.

§

FTC & NC Attorney General

If you believe you are the victim of identity theft or have reason to believe your personal information has been misused, contact the FTC and/or your state Attorney General's office.

  • FTC: 600 Pennsylvania Ave NW, Washington, DC 20580 • 1-877-IDTHEFT (438-4338) • ftc.gov
  • NC Attorney General — Consumer Protection Division: 9001 Main Service Center, Raleigh, NC 27699-9001 • 1-877-566-7266 or 1-919-716-6400 • ncdoj.gov

North Carolina residents are advised to report any suspected identity theft to local law enforcement or to the North Carolina Attorney General.

Questions? We're Here to Help.

For specific questions about the technology incident and its impact on your student or family, please reach out to our technology team directly. Please note that responses may be delayed as staff are fully engaged in the restoration effort.

tech.support@onslow.k12.nc.us