Circleville, Ohio, restored affected municipal systems after ransomware activity, but the city has not disclosed when the incident began or which public services were affected.
“The city did not pay a ransom,” Mayor Michelle Blanton said in a statement reprinted Aug. 26 by the Circleville Herald. Affected systems were rebuilt from clean environments or recovered through established procedures, then reviewed before being returned to service, she said.
The city and its technology provider isolated systems, examined potentially affected devices and began recovery work after detecting the activity. Blanton said the investigation and post-incident security review are ongoing.
A separate account raises questions about the incident’s scope and the timing of coordination with county officials. The community group Teays Valley Against Overgrowth said in a Facebook post that Pickaway County Emergency Management Agency Director Tiffany Nash told county commissioners Tuesday that state officials had alerted her to a potential ransomware incident affecting the city and Police Department.
The group did not identify which police systems were affected or establish an interruption to police or other public-safety operations. DysruptionHub found no published county minutes or meeting recording that independently corroborated the account.
The Facebook post said Nash learned the incident occurred Aug. 14. Circleville’s statement did not provide an incident or detection date, and DysruptionHub found no official source independently corroborating Aug. 14.
Blanton said the city was not aware of evidence that sensitive information had been exfiltrated and would make notifications or take protective steps if new findings warranted them. As of Aug. 27, DysruptionHub had found no public claim of responsibility from a ransomware or extortion group.
The 2026 incident is at least the second publicly reported ransomware attack involving a Circleville municipal operation since 2023. A Jan. 1, 2023, attack on Circleville Municipal Court set the court back for weeks and forced employees to work with pen and paper until servers and computers could be replaced, Judge Elisa Peters told the Supreme Court of Ohio. LockBit claimed it stole 500 GB of court data, but the court did not confirm the group’s claim.
The city did not respond before the original Aug. 27 publication to questions about the detection date, the scope of any effect on police technology, when county and state officials were notified or when restoration was completed. DysruptionHub found no later public update answering those questions as of Sept. 6.