Ground.News Teenager Arrested for Cyber Attack on Northern Ireland Schools' IT System
Article Content
- •A 16-year-old was arrested for a cyber attack on the Education Authority's IT systems.
- •The attack locked students out of essential educational resources during the Easter holidays.
- •The investigation is ongoing, with the teenager released pending further inquiries.
A 16-year-old boy was arrested on April 15, 2026, in Portadown as part of an investigation into a cyber attack that disrupted the Education Authority's IT systems in Northern Ireland. The attack, reported on April 2, 2026, affected access to educational resources for potentially hundreds of thousands of students during the Easter holidays. The arrest was made under the Computer Misuse Act 1990, and the teenager has since been released pending further inquiries. The cyber attack specifically targeted the C2K network, which is essential for curriculum support in schools across the region. The Education Authority has apologized for the disruption caused to students preparing for exams. The investigation is ongoing, with police continuing to assess the full impact of the incident.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (15)
Following this threat?
Track Education Authority in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…