Featured artwork for the TorchLight update on the Spokane Public Schools cybersecurity incident

Spokane Public Schools Cybersecurity Incident: What We Know So Far

Spokane Public Schools is investigating a network security incident that took PowerSchool, payroll and other systems offline. Here is what has been confirmed, what has not been confirmed, and what local organizations can take from it while the investigation continues.

September 23, 2026 Author: Zach Carothers Reviewed By: Benjamin Ross 5 min read Spokane & Inland Northwest Cybersecurity & K-12
UPDATED: Sept. 25th at 1:45pm pst

Systems Remain Offline as the Investigation Continues

As of September 25, Spokane Public Schools is still working through the network security incident. PowerSchool and BusinessPlus, the district’s finance, HR and payroll platform, remained unavailable in the latest reporting while district staff and outside technical specialists continued the investigation and recovery process.

Teachers have continued using manual workarounds for attendance and other day-to-day functions. Despite the BusinessPlus disruption, the district has said it does not expect employees to miss payday.

PowerSchool has also said its investigation found no impact to PowerSchool-hosted products or data belonging to other PowerSchool customers. That is an important clarification and reinforces that PowerSchool being taken offline does not, by itself, mean the broader PowerSchool platform was compromised.

Executive Summary

Spokane Public Schools disclosed a network security incident after detecting suspicious activity Sunday night, September 20. PowerSchool, payroll and other systems were taken offline while the district and outside specialists investigate.

So far, the district has said the identified impacts involve staff. No student-data exposure, ransomware group, attacker or initial point of entry has been publicly confirmed.

TorchLight is headquartered in Liberty Lake, supports K-12 districts across Washington and is available to districts through the WLS343 procurement contract. We will keep this post updated as Spokane Public Schools releases meaningful, verified information.

What We Know Right Now

This one is too close to home in the most literal sense.

TorchLight is headquartered in Liberty Lake, and Spokane, Spokane Valley, Liberty Lake and Coeur d’Alene are not just markets we added to our website because we wanted a larger service area. This is our home. Our employees live here. Our families live here. Our clients and friends live here.

So when Spokane Public Schools disclosed that it was responding to a cybersecurity incident this week, it caught our attention for reasons that go well beyond a cyber headline.

Spokane Public Schools serves around 29,000 students across 58 different schools. On Sunday night, September 20, the district detected what it described as a “network security incident”, and, as of Tuesday, PowerSchool and the district’s payroll system were subsequently taken offline while they investigate further.

The district has brought in a third-party technical expert, and Superintendent Adam Swinyard said Tuesday that, so far, the investigation had only identified impacts involving district staff. However, the district has also stated that it’s still too early to determine the full scope of the incident, what information may have been affected or who may be responsible, which is usually the case this early into an investigation.

Right now, there is a lot we don’t know. And when something like this happens in our own community, getting the facts right matters more than getting a dramatic headline out first.

Spokane Public Schools informed families Monday that it was responding to a network security incident and had taken several systems offline as a precaution. PowerSchool and the district’s payroll system were among the affected systems, and outside specialists have been brought in to investigate. Superintendent Swinyard said that so far, the investigation had found impacts involving district staff.

There are also several things that have not been established publicly.

No student-data exposure has been confirmed.
No ransomware group or other attacker has been identified.
The cause and initial point of entry have not been disclosed.
PowerSchool being offline does not mean PowerSchool itself was compromised.

Calling this a data breach, ransomware attack or PowerSchool compromise right now would be speculation.

For the moment, the most accurate description is exactly what the district called it: a network security incident.

Why We Are Paying Close Attention

Even without knowing the cause, what is happening at Spokane Public Schools demonstrates how quickly a cybersecurity problem can become an operational problem.

Take a critical platform offline and suddenly IT is only one piece of the response. Employees need workarounds, leadership needs information, and families need answers. Communications teams need to explain what is happening while investigators are still figuring it out.

That’s especially true in education, where student information systems, payroll, communications, identity, transportation and third-party applications all contribute to keeping a district operating. And in this particular case, TorchLight is more than a local observer.

We are an approved cybersecurity vendor through Washington Learning Source, available to Washington districts through the WLS343 procurement contract, and already support K-12 districts across Washington. That work gives us a close view of the cybersecurity, compliance and operational challenges school technology teams are dealing with every day.

It does not give us inside information about the Spokane Public Schools investigation, and we will not pretend that it does.

What it does mean is that when something like this happens in our own backyard, we pay attention.

What Local Organizations Can Take From This Today

We do not need to know how the Spokane incident started to ask a few useful questions about our own environments.

01

Could we operate if one of our critical systems disappeared tomorrow?

Know which systems your organization depends on and what happens when one becomes unavailable.

02

Have we actually tested recovery?

Having a backup is different from proving that you can restore from it. Test the restore.

03

Is MFA really enabled everywhere that matters?

Administrator accounts, email, remote access and cloud management deserve particular attention.

04

Does everyone know what happens when an incident becomes real?

Who contacts insurance? Legal counsel? Leadership? Employees? Customers or families? Who decides when outside notification is required?

Those questions apply far beyond education. They are the same questions we work through with organizations using managed cybersecurity, co-managed IT and security and formal cybersecurity assessments.

For Washington school districts specifically, we also maintain a Washington K-12 Cybersecurity Compliance Checklist covering several of the controls and requirements districts are already being asked to demonstrate.

What About Student Information?

As of this update, Spokane Public Schools has not publicly confirmed that student information was compromised.

If investigators determine that protected information was acquired by an unauthorized person, what happens next will depend on exactly what information was involved and which legal notification requirements apply.

That is another reason we are going to wait for verified findings rather than guessing at what investigators may discover.

We Will Keep This Updated

This story is still developing.

The investigation may tell us considerably more about how the incident occurred, which systems or information were affected, how Spokane Public Schools contained it and what remediation follows.

As the district releases meaningful, verified information, we will continue updating this article throughout the discovery, recovery and remediation process.

This is something we plan on being more consistent about when serious cybersecurity or IT events affect Spokane, Spokane Valley, Liberty Lake, Coeur d’Alene and the surrounding Inland Northwest.

This is our home.

When something happens here, our goal is to help separate what is known from what is being speculated about, explain why it matters and give local organizations something useful they can take away from it.

There will always be plenty of people willing to turn a developing cybersecurity incident into a scary headline.

We would rather help you understand it.

Questioning your own organization’s readiness?

If this incident has you taking a harder look at your own environment, talk with our local TorchLight team.

Sources & Resources