Cherokee County School District
bd_aaebd69abc7831a5 · schema v1 · pii pii-v1
Full breach record for Cherokee County School District →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
Cherokee County School District Responds to Network Security Incident. Cherokee County School District: The Cherokee County School District is facing a cybersecurity incident affecting its computer systems and is actively collaborating with the FBI, SLED, and the local sheriff to determine the extent of the breach. As a precaution, the use of computer systems has been suspended, and Monday classes will proceed without technology. The district is focused on restoring its critical operations while ensuring data security and has promised to keep the community informed as developments occur. Linked ransomware group: interlock.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Mar 15, 2025
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteinterlockbd_fd871bfcff1e1ec62025-03-16 · +1dCandidate
Regulatory filings (1) · sorted by filing gap
- South Carolina State AGbd_87089532070cfe952025-09-03 · +172dVerified by operator
Filing propagation · 2 filings
View merged incident ↗Pattern: first filing Mar 15, last Sep 3 (SC) — a 172-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
interlock
According to ransomware.live, Interlock is a ransomware group first observed in September 2024 that targets critical infrastructure sectors including healthcare, government, education, and technology across North America and Europe using double-extortion, with 57+ claimed victims including a major US dialysis provider exposing over two million patient records.