Circleville, Ohio, restored municipal systems after ransomware activity prompted officials to take city computers offline Aug. 6, delaying card payments and other computer-based work.
“The city did not pay a ransom,” Mayor Michelle Blanton said in a statement reprinted Wednesday by the Circleville Herald. Affected systems were rebuilt from clean environments or recovered through established procedures, then reviewed before being returned to service, she said.
The city and its technology provider isolated systems, examined potentially affected devices and began recovery work after detecting the activity. Blanton said the investigation and post-incident security review are ongoing.
The incident became public Aug. 6. A repost of the city’s initial alert preserved on Reddit said a ransomware notice appeared on one computer, followed by additional notices as employees accessed their computers.

The city took municipal computers offline on the advice of outside experts while it investigated and contained the threat. Emergency dispatch, water, wastewater and telephone systems were not directly affected, and the city remained operational, according to the alert.
A separate account raises questions about the incident’s scope and the timing of coordination with county officials. The community group Teays Valley Against Overgrowth said in a Facebook post that Pickaway County Emergency Management Agency Director Tiffany Nash told county commissioners Tuesday that state officials had alerted her to a potential ransomware incident affecting the city and Police Department.
The group did not identify which police systems were affected or establish that police, dispatch or 911 operations were interrupted. DysruptionHub found no published county minutes or meeting recording that independently corroborated the account.
The Facebook post dates the incident to Aug. 14, conflicting with the city alert that reported ransomware notices Aug. 6.
Blanton said the city was not aware of evidence that sensitive information had been exfiltrated and would make notifications or take protective steps if new findings warranted them. As of Thursday, DysruptionHub had found no public claim of responsibility from a ransomware or extortion group.
The 2026 incident is at least the second publicly reported ransomware attack involving a Circleville municipal operation since 2023. A Jan. 1, 2023, attack on Circleville Municipal Court set the court back for weeks and forced employees to work with pen and paper until servers and computers could be replaced, Judge Elisa Peters told the Supreme Court of Ohio. LockBit claimed it stole 500 GB of court data, but the court did not confirm the group’s claim.
The city had not responded by publication time to questions about the detection date, the scope of any effect on police technology, when county and state officials were notified, or when restoration was completed.