Clarksville ISD
Attack Intelligence
Clarksville ISD was compromised in a ransomware attack attributed to interlock in November 2025. The organization, operating in the Education sector in United States, was added to the group's data leak site as part of an extortion campaign.
interlock operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
Once again, we see how a certain school organization, Clarksville ISD, was attacked and compromised due to the negligence and irresponsibility of employees with other people's data, that is, other people, as a result of which a large amount of confidential data was compromised, including the SNN of all students for the entire year, as well as all employee data, including SNN, banking transactions, and financial components.
Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2026-20131, which may have been leveraged as initial access vectors or for lateral movement.