DisclosureLens
GLOBALUnknownRansomwareMedusaLow

The Glendale Unified School District

bd_cb4927082a662c56 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Dec 6, 2023

To disclose

Affected

Not disclosed

Linked

5 filings

Confidence

60%
Full breach record for The Glendale Unified School District

Press / market disclosure — not a breach-notification filing

A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.

Ransomware attack hits Glendale Unified School District - Daily News. Glendale Unified School District: The Glendale Unified School District was the victim of a ransomware cyberattack, affecting several of its computer systems, which led officials to advise students and staff to avoid using computers provided by the district. The details of the security breach are not yet known, but an investigation is underway with the help of the Glendale Police Department. Cautionary advice has been given to students and parents, including avoiding the use of devices connected to the district's computer systems and being wary of suspicious links and programs. Linked ransomware group: medusa.

Incident timeline — mostly unverified

? — ?

Breach window unknown

Dec 6, 2023

Press report

Corroborated · see linked filings

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Attack → press

Compliance clock

Not assessable

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (2)

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings

View merged incident ↗
PressDec 6 · first · this page

Pattern: first filing Dec 6, last Aug 9 (CA) — a 247-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market reportThis record

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • incident type + narrative only (may be machine-translated)
  • discovery date
  • materiality
  • affected count
  • data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.

About this groupFirst seen 2023-01-11

medusa

According to ransomware.live, Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.

565 tracked hereFull profile →