Skip to content
DysruptionHub registry workspace

Cyber Incident Register

Updated Jul 27, 2026

A continuously updated registry of publicly reported cybersecurity incidents affecting organizations, governments, critical infrastructure and communities.

Search incidents

Published records

Incident activity

Refine incidents

Refine incidents

Status
Active Resolved
More criteria
DD-CIT transparency
Ransomware confidence
Not applicable Confirmed
  • Jul 26, 2026

    AnMed malware outage disrupts care across regional sites

    New report available to Sustainers
    AnMed Anderson, South Carolina

    AnMed confirmed on July 26, 2026, that malware disrupted network, phone and internet systems across its regional health system, closing or limiting numerous outpatient, imaging and specialty services while emergency care continued. MyChart and normal discharge paperwork were unavailable, patient diversions were confirmed, and an external report described a 72-hour extortion deadline that AnMed had not verified.

  • Jul 20, 2026

    Dallas websites taken offline after external cyber threat

    New report available to Sustainers
    City of Dallas Dallas, Texas

    City of Dallas security systems detected a possible threat originating outside the municipal network on July 20, 2026, and automatically took three public websites offline. The sites returned after more than 15 hours, while officials reported no network intrusion or loss of city data and said essential emergency, payment and permitting services remained available.

  • Jul 20, 2026

    Sumner County Schools network breach delays opening

    New report available to Sustainers
    Sumner County Schools Gallatin, Tennessee

    Sumner County Schools discovered unauthorized access to its network on July 20, 2026, and opened an investigation with law enforcement and forensic specialists. The incident disrupted registration and forced the district to delay the first day of school from August 4 to August 10.

  • Jul 19, 2026

    Tidewater cyberattack disrupts internet across coastal Maine

    New report available to Sustainers
    Tidewater Telecom Nobleboro, Maine

    Malicious traffic disrupted Tidewater Telecom and Lincolnville Communications internet service across coastal Maine beginning July 19, 2026, leaving some connections unusable and significantly limiting Damariscotta Town Office services. The providers reported near-normal service July 21, and their status page subsequently showed customer internet operational with no recurrence through July 26.

  • Jul 16, 2026

    Ransomware suspends fairlife U.S. production

    New report available to Sustainers
    fairlife Coopersville, Michigan

    Coca-Cola confirmed that ransomware-related unauthorized access to fairlife systems, including production-related infrastructure, led to a temporary suspension of U.S. production while Canadian production and product safety were unaffected. Anubis later claimed it encrypted systems and stole about 1 TB of data, but the company did not verify the attribution or data-theft allegation and no restoration notice was found by July 25.

  • Jul 15, 2026

    Cyber incident disrupts Milford, New Hampshire services

    New report available to Sustainers
    Town of Milford, New Hampshire Milford, New Hampshire

    The Town of Milford, New Hampshire, confirmed unauthorized activity affecting municipal computer systems after phone, internet, clerk, billing, payment and meeting disruptions began July 15, 2026. On July 22, several systems remained offline for analysis, backup processes were still in use, and officials said the cause and full extent had not been confirmed.

  • Jul 14, 2026

    TruStage cyber incident disrupts credit union claims

    Report available to paid members
    TruStage Madison, Wisconsin

    TruStage continued investigating and restoring systems after a cybersecurity incident it reportedly identified July 11, 2026, with account access, transactions, online requests, payments and claims still impaired in a July 24 update. The company reportedly believes an employee may have inadvertently downloaded a malicious file while installing a legitimate tool, but data impact, ransomware and actor attribution remain unresolved.

  • Jul 13, 2026

    Cyber incident disrupts Cedar Crest College systems

    Report available to paid members
    Cedar Crest College Allentown, Pennsylvania

    Cedar Crest College said investigation and controlled restoration remained active July 20, 2026, after a cyber incident disrupted campus applications, network drives, OneDrive and other file-sharing services. The college has not confirmed data access or ransomware, and NightSpire's claim remains uncorroborated.

  • Jul 12, 2026

    Greenfield DDoS attack disrupts California internet

    Report available to paid members
    Greenfield Communications Sacramento County, California

    A large-scale distributed denial-of-service attack disrupted Greenfield Communications internet, television and phone service in Rancho Murieta and other California communities beginning July 12, 2026. Most customers were restored July 14, but IP-geolocation problems continued affecting streaming applications and some remote work through July 17.

  • Jul 10, 2026

    Progress ShareFile zero-day disrupts storage access

    Report available to paid members
    Progress Software Corporation Burlington, Massachusetts

    Progress Software traced its July 2026 ShareFile Storage Zone Controller shutdown to a high-severity path traversal zero-day affecting all 5.x and 6.x versions and initially released versions 5.12.5 and 6.0.2. The containment action disrupted access to customer-managed files until July 14, but Progress said it had no indication of unauthorized access to customer accounts or data and had identified no active threat.

  • Jul 9, 2026

    Greene County cyber incident disrupts government services

    Report available to paid members
    Greene County, Georgia Greensboro, Georgia

    Greene County, Georgia, took its government network offline after identifying a cybersecurity incident July 9, 2026, disrupting payments and public-request processing across multiple county offices while 911 and sheriff operations continued. The county said investigators had found no evidence of accessed or exfiltrated information, but online tax payments were still unavailable July 26 and the county had not announced full restoration or an investigative conclusion.

  • Jul 7, 2026

    St. Lucie County clerk website compromise causes redirects

    Report available to paid members
    St. Lucie County Clerk and Comptroller Fort Pierce, Florida

    The St. Lucie County Clerk and Comptroller's externally hosted public website was compromised July 7, 2026, causing an hours-long homepage outage and redirecting some links to an unauthorized third-party site. Staff removed a malicious script and restored the site from a known-good backup; the clerk confirmed the compromise July 8, reported no evidence of access to internal systems or their data, and warned of possible slower performance during database re-indexing.

  • Jul 5, 2026

    Pennington County cyber incident disrupts offices

    Report available to paid members
    Pennington County, South Dakota Rapid City, South Dakota

    Pennington County identified a cybersecurity incident by July 5, 2026, and closed most public-facing offices July 6. Offices reopened July 7, but payments, vehicle registrations, records, permits and meeting livestreams remained limited during staged recovery. The county website still warned of significant service impacts July 26 while personal-information effects, the attack mechanism, ransomware and attribution remained unresolved.

  • Jul 3, 2026

    Jacksonville, Texas cyber incident disrupts city systems

    Report available to paid members
    City of Jacksonville, Texas Jacksonville, Texas

    Jacksonville, Texas, detected suspicious network activity July 3, 2026, took affected municipal systems offline and used workarounds while some online city services were unavailable. By July 26 the city website and online payment portal were operating, but no official full-restoration, forensic, breach, ransomware or attribution update had been published.

  • Jun 28, 2026

    D.C. Housing Authority cyberattack disrupts systems

    Report available to paid members
    District of Columbia Housing Authority Washington, District of Columbia

    DCHA discovered a cybersecurity incident June 28, 2026, shut down its network and restored services in phases. On July 17 it confirmed that a limited subset of data including sensitive information was compromised and announced credit monitoring, while Interlock's separate ransomware and 1,660 GB theft claim remained unverified.

  • Jun 26, 2026

    Delaware County cyberattack disrupts county systems

    Delaware County, Pennsylvania Media, Pennsylvania

    Delaware County, Pennsylvania, identified unauthorized intrusion attempts on June 26, 2026, and shut down network systems to protect sensitive information. Attackers gained limited access to the county network and data, while phones, servers, financial software, libraries and other public services were disrupted; some network issues remained publicly flagged on July 26.

  • Jun 24, 2026

    Settra claims American Color Imaging after Iowa outage

    American Color Imaging Cedar Falls, Iowa

    American Color Imaging experienced a systems outage from June 24 to July 1, 2026, that paused production, held submitted orders, delayed customer communications and disabled an ordering platform. Settra publicly claimed on July 16 that it stole 653 GB of data, but ACI has not confirmed a cyberattack, unauthorized access, data theft or the actor's involvement.

  • Jun 23, 2026

    Akron schools cyber incident closed all buildings

    Akron Public Schools Akron City School District, Ohio

    Akron Public Schools detected and contained a June 23, 2026, cyber incident that caused a districtwide network outage and closed every district building June 24. Most programs, offices and athletics resumed June 25, but online credit recovery remained canceled through June 26 while external specialists investigated the incident's nature and scope.

  • Jun 22, 2026

    Wise County Sheriff’s Office cyberattack disrupts records access

    Wise County Sheriff's Office Decatur, Texas

    The Wise County Sheriff's Office said hackers hit its systems twice during the week before June 22, 2026, preventing records retrieval and printing of incoming public-information requests. Logged and saved requests were lost or inaccessible and had to be rebuilt from sent email files. The deadline suspension ended July 5 and official request channels are currently available, but full restoration and recovery of missing requests remain unconfirmed.

  • Jun 19, 2026

    Stack Sports card breach halted Utah soccer registration

    Stack Sports Plano, Texas

    Utah Youth Soccer disabled player and administrator registration through Sports Connect after members reported unauthorized card charges linked to recent registrations. On June 24, 2026, Stack Sports confirmed a breach involving card information transmitted to its payment functionality, said the source had been neutralized and all affected systems restored, and began identifying affected people for notification and protection services; the exposure window, affected population and intrusion method remain undisclosed.

  • Jun 17, 2026

    University City cyberattack disrupted services

    City of University City University City, Missouri

    University City, Missouri, confirmed that malicious cyber activity caused a network outage first publicized June 17, 2026, disrupting permitting, public-record access, card processing and online bill payment. By July 23, some services had returned, recovery remained in progress, and the city said it had found no evidence that personal information was accessed or removed.

  • Jun 16, 2026

    River Financial Corporation ransomware incident

    River Financial Corporation Prattville, Alabama

    River Financial Corporation disclosed that an unauthorized actor accessed its network, including River Bank & Trust, on or about June 16, 2026, deployed ransomware across portions of its servers and removed data. Certain operations were affected, but River had not identified the affected services, data categories or customer PII involvement. A July 17 SEC amendment reported four related class actions and said the incident's full scope, impact and potential materiality remained unresolved.

  • Jun 11, 2026

    NAIC PeopleSoft incident disrupts insurer designations

    National Association of Insurance Commissioners Kansas City, Missouri

    NAIC detected unauthorized access to its PeopleSoft environment on June 11, 2026, after exploitation of a zero-day vulnerability. Data was acquired and published, while suspended credit-rating feeds disrupted insurer investment designations and online invoice payments remained unavailable in the latest official update.

  • Jun 11, 2026

    Prince George County cyber incident disrupted services

    Prince George County Prince George, Virginia

    Prince George County, Virginia, said a June 11, 2026 cyber incident disrupted phones, internet and online payments before systems were secured and normal operations resumed. The county said personal data may have been accessed and offered identity monitoring, while RansomHouse's ransomware and attribution claims remain unverified.

  • Jun 10, 2026

    Spartanburg County network outage disrupted services

    Spartanburg County, South Carolina Spartanburg, South Carolina

    Spartanburg County isolated portions of its network after detecting questionable activity around June 10, 2026, causing weeks of disruption to phones, courts, payments, records and other services. Core connectivity returned June 29, but isolated delays could continue during validation; officials found no evidence of data compromise and did not confirm ransomware or an actor.

  • Jun 9, 2026

    Onslow County Schools cyberattack disrupted phones

    Onslow County Schools Onslow County Schools, North Carolina

    Onslow County Schools detected unauthorized criminal activity June 9, 2026, disrupting phones, internet, digital services, testing and graduation livestreams across the district. The district later said a relatively small portion of data was exfiltrated; by June 23 the attack was contained and major services were returning, but staged infrastructure restoration and the data-impact review remained underway.

  • Jun 8, 2026

    Acworth cyber incident followed by INC Ransom claim

    City of Acworth Acworth, Georgia

    The City of Acworth, Georgia, documented network outages and possible service interruptions June 8, 2026, then confirmed June 18 that a cybersecurity incident had affected certain computer systems and that all systems were restored. INC Ransom later claimed the city, alleged possession of municipal data and threatened release, but Acworth has not confirmed the actor, data theft, ransomware, a demand or payment.

  • Jun 7, 2026

    Evanston Township High School ransomware closure

    Evanston Township High School District 202 Evanston Township High School District 202, Illinois

    Evanston Township High School District 202 confirmed that a June 7, 2026 ransomware attack disrupted campus safety systems, phones, internet, staff accounts and core servers, closing campus June 8–9. Campus reopened June 10, but technology recovery continued into late July with unavailable portals and records, phased service restoration and temporary workarounds.

  • Jun 5, 2026

    Lewis Brisbois cyberattack restricted remote work

    Lewis Brisbois Los Angeles, California

    Lewis Brisbois Bisgaard & Smith LLP restricted outside access to internal networks after a June 2026 cyberattack and directed remote and hybrid employees to work from offices or use firm-issued computers. The public record does not establish whether attackers successfully entered the network, accessed client or employee data, deployed ransomware, made an extortion demand or caused a client-service outage.

  • Jun 4, 2026

    Kittson County cyber report limited DMV services

    Kittson County Hallock, Minnesota

    Kittson County reported a cyber incident involving its emergency-services network, prompting Minnesota IT Services to block the county’s access to state motor-vehicle systems as a precaution. Full DMV services were temporarily unavailable while limited tab payments and Department of Natural Resources transactions continued; emergency services remained operational, and ransomware, data theft and NightSpire attribution were unconfirmed.

  • Jun 2, 2026

    Bowman Parks files encrypted in cyberattack

    Bowman Parks & Recreation Bowman, North Dakota

    Bowman Parks & Recreation disclosed at a June 2, 2026, city commission meeting that a cyberattack encrypted every department file and connected thumb-drive backups, making the records inaccessible. The files were later decrypted with outside expert assistance, but the attack date, initial access method, ransom or payment status, data-copying scope and public-facing service impact remain unresolved.

  • May 14, 2026

    Krum Public Library ransomware disrupted Wi-Fi

    Krum Public Library Krum, Texas

    Krum Public Library confirmed that a May 14, 2026, ransomware attack disrupted computer access, printing and Wi-Fi and temporarily limited checkout to five items. The library later secured its network, and current official pages again advertise normal services; unauthorized file access was confirmed, while NightSpire's claim to have stolen 50 GB remains unverified.

  • May 11, 2026

    Mountain Park, Oklahoma Town Hall network breach

    Town of Mountain Park Mountain Park, Oklahoma

    Mountain Park, Oklahoma, identified unauthorized access to municipal systems on May 11, 2026, and requested assistance from the Oklahoma State Bureau of Investigation. The town said administrative email was disrupted, while emergency services and utility operations were not interrupted; the access method, responsible party and possible copying of municipal data remain unresolved.

  • May 6, 2026

    IT Curves attack claim followed paratransit disruption

    IT Curves Allegany County, Maryland

    Allegany County Transit said a cybersecurity incident involving a third-party scheduling vendor required riders with May 6–7, 2026, pickups to call and confirm their trips. Public evidence points to IT Curves as the likely vendor, while Ababil of Minab separately claimed it compromised IT Curves and wiped and stole data; neither the vendor link nor the actor’s technical claims were confirmed.

  • Apr 4, 2026

    Karl Auto Group cyberattack disrupted Iowa dealerships

    Karl Auto Group Webster City, Iowa

    Karl Auto Group discovered on April 4, 2026, that an unauthorized third party had accessed business systems, disrupting phones and computers across its Iowa dealership operations. The company said files may have contained sensitive customer and employee information, while RansomHouse separately claimed Karl Chevrolet and alleged encryption; ransomware, exfiltration and a connection to that actor remain unconfirmed.

  • Nov 24, 2025

    Northwest Iowa Community College network intrusion

    Northwest Iowa Community College Sheldon, Iowa

    Northwest Iowa Community College experienced a computer network disruption in late November and early December 2025 that canceled on-campus classes and impaired campus technology services. The college later confirmed unauthorized activity and said information may have been accessed or downloaded between November 24 and November 26, 2025. Its July 2026 breach filing identified 16,004 Iowa residents whose names and Social Security numbers were potentially affected.