← All incidents
Resolved, last updated 2023
K-12 districtMedusa ransomwareData leakNotification failure

Minneapolis Public Schools Ransomware

February 2023. The most graphic illustration of what "student records" can actually contain, and a case study in failed breach notification. The district told families no personal information was compromised. It was wrong.

What happened

In February 2023, the Medusa ransomware gang breached Minneapolis Public Schools and, after the district declined to pay a $1 million ransom, dumped the stolen files online. Reporting counted more than 189,000 files (some accounts put the figure near 300,000) containing records on students across the district.

Confirmed exposed

  • Sexual assault reports, psychiatric hospitalizations, abuse and truancy files, suicide attempts
  • School building blueprints, surveillance camera locations, and security infrastructure

Confirmed not exposed

  • The district initially told families no personal information was compromised, a statement contradicted by the leaked files

Why it belongs in this library

"Student records" is not a tidy category of names and grades. It can include the single most sensitive facts about a child's life. This incident is also a notification failure: the first thing families heard understated what had happened.

Sources

  1. Campus Safety Magazine — Over 189,000 Files Leaked in Minneapolis Public Schools Data Breach (2023)
  2. The 74 — Kept in the Dark: Inside the Minneapolis Schools Cyberattack (2023)

This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].

Minneapolis Public Schools Ransomware: February 2023 | Ask Before You App