A ransomware incident disrupted parts of Ellis County, Kansas, government technology systems Thursday, leaving some public services unavailable or delayed and forcing departments to use temporary procedures.
County officials said they became aware of the incident early Thursday, isolated affected systems and brought in cybersecurity specialists, according to a statement published by Hays Post.
Some services could remain disrupted for days or weeks, the county said. Officials did not identify the affected departments or applications and advised residents to contact individual departments before conducting county business.
Officials said 911 and emergency public-safety response remained operational. They said the incident appeared limited to county government systems, with no evidence at the time that people, businesses or other agencies were affected.
Ellis County said it was working with local law enforcement, the Kansas Highway Patrol and the Kansas Bureau of Investigation to determine the incident’s scope and cause. Officials warned residents to use caution with messages from ellisco.net while the investigation continues.
The county said it had no evidence at the time that personal or sensitive information had been accessed or obtained. The investigation remained open, and officials said they would notify affected people if they determine personal information was involved.
Officials have not publicly identified the affected systems, ransomware family or responsible threat actor. The public record also does not establish whether attackers stole data, issued a ransom demand or received payment.
The disruption follows two other recent technology incidents involving Kansas local governments. Suspicious activity at the Douglas County Sheriff’s Office interrupted online inmate reports and fingerprint scheduling in August, while Fort Scott restored municipal systems after a ransomware attack forced City Hall and its core network offline.
As of Friday, Ellis County had not issued another restoration notice. The county said containment, investigation and recovery were continuing, but it did not set a timetable for full service restoration.