The Hidden Threat to Roanoke's Digital Infrastructure

Recent school cyber incidents are highlighting a broader challenge as hospitals, utilities and public services rely more heavily on connected technology.

Recent school cyber incidents are highlighting a broader challenge as hospitals, utilities and public services rely more heavily on connected technology.

Roanoke, VA

Author: Roanoke Rambler Staff,  Tina Charisma Lead

Published: 11:58 PM EST August 25, 2026

Edited: 11:59 PM EST August 25, 2026

When Roanoke-area students logged into Canvas this spring, few realized they had become part of a nationwide cybersecurity breach affecting hundreds of school districts and universities.

The April and May attack, attributed to the hacking group ShinyHunters, affected Roanoke City and Roanoke County Public Schools along with school systems nationwide, exposing information including names, email addresses, student identification numbers and message histories.

It was the latest in a series of cybersecurity incidents affecting schools in the region. In late 2024, a breach of the PowerSchool student information system affected Botetourt County and Salem City Schools after hackers gained access to data stored by the software vendor. Months later, Botetourt County Public Schools experienced a direct network intrusion. School officials later confirmed that some compromised information had appeared on the dark web, prompting an investigation involving local, state and federal law enforcement.

The school breaches are not isolated events. They are part of a broader trend as hospitals, utilities, governments and businesses become increasingly dependent on connected technology — and increasingly vulnerable when those systems are compromised.

Many cyber incidents today do not begin by targeting a specific community. Instead, they exploit widely used software vendors that serve thousands of organizations at once. That means a school district, hospital or local government can become caught up in a breach simply because it relies on the same software platform as hundreds of other institutions — a pattern that played out in both the Canvas and PowerSchool incidents.

Virginia's annual Information Security Report, published by the Virginia Information Technologies Agency, identifies ransomware, third-party software compromises and data breaches as ongoing risks facing public-sector organizations across the Commonwealth. The U.S. Government Accountability Office has similarly warned that ransomware continues to threaten critical infrastructure sectors including healthcare, energy, manufacturing and transportation.

For Roanoke, that means cybersecurity is no longer simply an issue for information technology departments. It has become part of the digital infrastructure that supports everyday life.

"Human error continues to be one of the most significant" cybersecurity threats, said B. Bagby, head of the Center for Cybersecurity Education at Virginia Western Community College.

"This is less about how technologies are changing, and more about how human interactions are always going to be a major factor," Bagby said. "From weak passwords to falling for phishing attempts, to simple mishandling of information and sensitive data."

While sophisticated cyberattacks often capture headlines, Bagby said many successful breaches begin with everyday mistakes.

Artificial intelligence is also reshaping the threat landscape, according to Bagby.

"AI is changing the landscape of cybersecurity threats," he said. "The attacks themselves may still be common, such as ransomware and data theft, but AI-assisted attacks can be faster, more personalized and more advanced than organizations are able to respond to quickly."

Bagby said AI allows attackers to produce more convincing phishing emails, automate reconnaissance and personalize attacks at a scale that would have been difficult only a few years ago, rather than creating entirely new forms of cybercrime.

Organizations that store large amounts of personal or sensitive information remain among the most attractive targets, Bagby said.

"Like the rest of the country, industries that carry a lot of private data are high-value targets," he said. "Healthcare, banking and manufacturing are all common targets."

For residents, the consequences of a successful cyberattack can range from temporary service disruptions to the exposure of personal information — even when they themselves have done nothing wrong.

"Every piece of data that is gathered on a person or business becomes a threat," Bagby said.

Medical forms, social media activity, online searches, vehicle data and countless other records can be combined into detailed profiles if stolen or mishandled.

"Too many leaders have decided problems can be solved by gathering more data from their consumers," Bagby said. "Unfortunately, this makes cybersecurity attacks more likely to be successful. The level of detail that can be obtained on individuals is staggering to consider."

Despite the growing threat, Bagby said he believes organizations across the region are working to strengthen their defenses.

"More communication with each other is one of the major keys to our community being resilient to cyberattacks," he said. "Roanoke has a strong technical community. There are a fair number of opportunities for us to come together and share our skills and experiences. We need more of those opportunities, and more participation from local leaders and businesses."

Roanoke City Public Schools says protecting student and staff information has become an ongoing priority. The division recently received the Trusted Learning Environment (TLE) Seal from the Consortium for School Networking, becoming only the third school division in Virginia to earn the national designation. The recognition is awarded to school systems demonstrating comprehensive practices for protecting student data and strengthening cybersecurity governance.

School officials said cybersecurity is embedded in multiple School Board policies and remains an ongoing focus as schools continue expanding their use of digital learning tools. The recognition reflects a growing effort by school systems to strengthen cybersecurity before — not just after — major incidents occur.

A "State of Cybersecurity" briefing delivered to the Roanoke City School Board this week put numbers behind that claim. District technology officials told board members that more than 80 percent of K-12 school divisions nationally now face recurring phishing, scam and business-email-compromise attempts, and that more than half of American districts have logged a cyber incident in the past year, frequently traced to stolen administrative credentials that open the door to ransomware. To counter that exposure, RCPS has layered five lines of defense: Barracuda email filtering that screens out phishing and malicious links before they reach staff inboxes, CrowdStrike endpoint software that automatically contains advanced malware in real time, Microsoft cloud-governance tools that flag unusual elevated-privilege activity across the district's Office 365 environment, VMware network segmentation that limits server access on a strict role-by-role basis, and staff themselves, whom officials described as an active human sensor translating written policy into daily habit. Over just the past 90 days, the district said, that architecture screened 3.1 million emails, blocked nearly 19,800 threatening messages before delivery, stopped 258 attempted exploits or spyware infections at the device level, and flagged cloud-privilege anomalies for real-time review — a volume of intercepted activity that, officials argued, would be unmanageable without automation.


The briefing also pointed to a less visible category of risk: the thousands of non-traditional, internet-connected devices — interactive whiteboards, security cameras, HVAC controllers — that now sit on school networks alongside student data systems. Nationally, officials noted, compromised third-party vendors and hardware account for nearly a third of public school breaches, a category distinct from the software-platform attacks that hit Canvas and PowerSchool. RCPS said it is now conducting a full audit of every such device across its schools and walling off building-automation and safety systems from core administrative databases through strict, "zero-trust" network segmentation, so that a compromised camera or thermostat cannot become a pathway into student records. The division has also begun rethinking security for its youngest and most vulnerable users: a new multifactor authentication system lets elementary students log in with simple picture sequences rather than hardware tokens or phones, while giving teachers the ability to reset a locked student account directly from the classroom console — cutting what could be a 24-hour helpdesk delay down to, in the district's words, zero minutes of lost instructional time.

While schools have become some of the most visible examples of cyber risk, education is only one part of a broader effort by public institutions to strengthen their digital resilience as essential services become increasingly connected.

For many residents, cybersecurity is invisible — until it is not. The recent school breaches offered a glimpse of how dependent modern communities have become on connected systems. Whether accessing healthcare, paying utility bills, communicating with local government or sending children to school, residents increasingly rely on digital networks operating behind the scenes. As more essential services move online, the challenge for Roanoke is no longer whether cybersecurity matters, but how well the community is prepared for the next disruption.

Support local, independent journalism!

Become a member

More Details