Quick Summary
AllegedExecutive Summary
North Slope Borough School District, a geographically isolated K-12 public school district in Alaska, was listed on the INC Ransom ransomware group’s dark web portal on September 28, 2026. This listing was identified through SOCRadar’s Dark Web Monitoring. Ransomware groups frequently target under-resourced public institutions due to factors such as limited IT staff, reliance on legacy infrastructure, and the urgent need to restore operations, creating an exploitable environment that groups like INC Ransom have repeatedly leveraged. In the 60 days preceding this listing, INC Ransom claimed 69 other victims. Over half of these victims are based in the United States, with Canada and Malaysia also appearing as secondary target geographies. The ransomware group’s activity primarily targets the Professional Services, Manufacturing, and Healthcare industries. However, US government and education entities are also consistently targeted. Notable victims listed during the same period include Otter Tail County (Minnesota), AHEAD, Welgen One, and Lemon Law.
Technical Analysis
SOCRadar’s query against the domain nsbsd[.]org returned no records. It is important to note that for public school districts, credential exposure often occurs through state education platform single sign-on providers or personal staff email aliases rather than the primary organizational domain. Such exposure points may fall outside the scope of this specific query, and a null result should not be interpreted as an indication of a clean security posture. The pathway from infostealer-captured credentials to ransomware deployment is applicable to public school districts just as it is to private sector organizations. Credentials harvested from a staff member’s personal device can grant access to critical systems such as Microsoft 365 or VPNs. To mitigate this risk, organizations should implement forced credential rotation and enforce multi-factor authentication.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.