Skip to content

Fort Scott restores systems after ransomware attack

The Kansas city shut down City Hall and its core network while public safety and industrial control systems remained isolated.

Red-brick Fort Scott City Hall, with a clock above the entrance and a stone City Hall sign in the foreground beneath a cloudy sky.
Fort Scott City Hall in Fort Scott, Kansas. The city closed the building and shut down its core network after detecting ransomware Aug. 18, 2026. (Randy Rasa/Googe Maps)

Fort Scott, Kansas, restored full municipal operations within six days of an Aug. 18 ransomware attack that forced City Hall and its core computer network offline.

The shutdown affected several noncritical machines at City Hall, the golf course, airport and freshwater facility. Public safety and industrial control systems remained operational because they were isolated from the affected network.

Stephen Mitchell, the city’s information technology director, told commissioners Sept. 1 that the attack was detected around 7:45 a.m. He said the first affected machine was isolated before the city shut down its core network and verified that public safety systems were working.

An Aug. 18 city notice attributed the closure to computer and phone problems and directed residents to use a payment drop box. Officials did not publicly identify the event as ransomware until Mitchell’s commission briefing two weeks later.

Draft minutes from the Sept. 1 meeting identify a phishing email as the suspected entry point. The public record does not establish the initial access method, compromised account or malware family.

Officials also identified and patched an antivirus problem related to a Microsoft update during the response. Mitchell said the issue had allowed antivirus software to restart, leaving some computers partially infected, according to Fort Scott Biz.

Two computers backed up through Microsoft OneDrive lost about one week of data. Available records do not explain whether the data was encrypted, corrupted or otherwise unrecoverable.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

The city has not publicly identified a threat actor or disclosed a ransom demand or payment. DysruptionHub found no confirmed evidence of data theft or public exposure and no matching public ransomware claim for the city or its website domain.

Full operations were restored by Sunday, Aug. 23, after city personnel worked extended shifts. A second local account from the Bourbon County Monitor said the Sept. 1 briefing was the city’s first public description of the attack.

During recovery, the city segmented its previously flat network so individual sites could be isolated. Officials also planned longer OneDrive backup retention and began evaluating a zero-trust architecture that could replace the city’s local Active Directory environment.

Joseph Topping

Joseph Topping

Joseph Topping is the founder and editor of DysruptionHub, reporting on cyber incidents and technology failures that disrupt public services, organizations and daily life.

All articles

More in Government

See all

More from Joseph Topping

See all