A cyberattack forced Colorado’s Salida School District to shut down its network after the intrusion began at about 6:30 a.m. on June 29 and was detected roughly two hours later. The incident damaged locally stored files on some network-connected devices, disrupted central-office administrative operations, and left some files potentially unrecoverable.
The district took all systems offline and retained specialists to investigate the attack and restore services safely. Officials said they had no indication that data had been accessed or exfiltrated at the time of disclosure, but forensic work remained ongoing; the district had not identified the attacker, intrusion vector, initial access method, ransomware involvement, or an extortion demand.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
In a July 2 notice, Salida School District said it had no apparent evidence that information had been accessed or extracted. Final forensic findings were still pending, and the district had not identified a threat actor, attack vector, ransomware, or extortion involvement.
Salida School District in Colorado detected a cyberattack about two hours after it began around 6:30 a.m., shut down its network and took systems offline. The incident damaged locally stored files, some of which may be unrecoverable, disrupted central-office administration, and prompted the district to engage incident-response specialists.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedatabreaches.net
Open sourcedysruptionhub.com
Open sourcesalidaschools.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.