Fort Scott, Kansas, restored full municipal operations within six days of an Aug. 18 ransomware attack that forced City Hall and its core computer network offline.
The shutdown affected several noncritical machines at City Hall, the golf course, airport and freshwater facility. Public safety and industrial control systems remained operational because they were isolated from the affected network.
Stephen Mitchell, the city’s information technology director, told commissioners Sept. 1 that the attack was detected around 7:45 a.m. He said the first affected machine was isolated before the city shut down its core network and verified that public safety systems were working.
An Aug. 18 city notice attributed the closure to computer and phone problems and directed residents to use a payment drop box. Officials did not publicly identify the event as ransomware until Mitchell’s commission briefing two weeks later.
Draft minutes from the Sept. 1 meeting identify a phishing email as the suspected entry point. The public record does not establish the initial access method, compromised account or malware family.
Officials also identified and patched an antivirus problem related to a Microsoft update during the response. Mitchell said the issue had allowed antivirus software to restart, leaving some computers partially infected, according to Fort Scott Biz.
Two computers backed up through Microsoft OneDrive lost about one week of data. Available records do not explain whether the data was encrypted, corrupted or otherwise unrecoverable.
The city has not publicly identified a threat actor or disclosed a ransom demand or payment. DysruptionHub found no confirmed evidence of data theft or public exposure and no matching public ransomware claim for the city or its website domain.
Full operations were restored by Sunday, Aug. 23, after city personnel worked extended shifts. A second local account from the Bourbon County Monitor said the Sept. 1 briefing was the city’s first public description of the attack.
During recovery, the city segmented its previously flat network so individual sites could be isolated. Officials also planned longer OneDrive backup retention and began evaluating a zero-trust architecture that could replace the city’s local Active Directory environment.