The Glendale Unified School District
bd_cb4927082a662c56 · schema v1 · pii pii-v1
Full breach record for The Glendale Unified School District →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
Ransomware attack hits Glendale Unified School District - Daily News. Glendale Unified School District: The Glendale Unified School District was the victim of a ransomware cyberattack, affecting several of its computer systems, which led officials to advise students and staff to avoid using computers provided by the district. The details of the security breach are not yet known, but an investigation is underway with the help of the Glendale Police Department. Cautionary advice has been given to students and parents, including avoiding the use of devices connected to the district's computer systems and being wary of suspicious links and programs. Linked ransomware group: medusa.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Dec 6, 2023
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Sitemedusabd_ecc1dfd09ac151892023-12-11 · +5dVerified
- Leak Sitemedusabd_4443d874ccf49fa92023-12-06Verified by operator
Regulatory filings (2) · sorted by filing gap
- California State AGbd_ca69de7f141c486b2024-01-10 · +35dVerified
- California State AGbd_815da93e41cf53b22024-08-09 · +247dVerified by operator
Filing propagation · 3 filings
View merged incident ↗Pattern: first filing Dec 6, last Aug 9 (CA) — a 247-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
medusa
According to ransomware.live, Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.