Skip to content

Adams County, Mississippi, ransomware attack

Summary

Adams County logo

A ransomware attack that Adams County officials said began April 17, 2026, disrupted county networks, digital court and public records, vehicle registration, and noncash payments while the sheriff’s separate systems remained available. Most county IT was restored by early May, but vehicle-tag services were still unavailable on May 19; no ransom demand, data-theft finding, responsible actor or final restoration date was publicly established.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

County officials told local media that an April 17 server crash was identified as ransomware, and Supervisor Kevin Wilson said the FBI confirmed an attack and was investigating. Our April 29 report documented those statements, the countywide outage, the absence of a ransom note and the lack of any public ransomware-group claim. Separately, DysruptionHub assesses with high confidence that malicious cyber activity caused a material county-government disruption.

The reported entry point was a sanitation department computer running Windows 7, after which the compromise spread through the county network. That account came from county IT Director Devonte Demby, but the available public record does not provide forensic findings, a malware family, an exploited vulnerability, persistence details or independent technical confirmation of the initial-access path. The record also does not establish whether information was accessed or removed.

Operational significance

The incident prevented employees from accessing digital civil and circuit-court records and disrupted public-records processing, vehicle-tag payments and other online county business. Offices used cash-only payment workarounds while normal electronic services were unavailable, and the county approved more than $250,000 in emergency network, equipment, monitoring and data-recovery work. The sheriff’s office remained operational because it used servers separate from the affected county environment.

By May 1, officials said about 70% of systems were back online and recovery was continuing. On May 19, the tax collector still could not process vehicle taxes, renew car tags or issue plates because the attack had disabled the county’s connection to the Mississippi Department of Revenue. This continuing public-service effect supports May 19 as the latest documented impact date.

Disclosure posture

The City of Natchez publicly alerted residents to a countywide internet outage on April 20 without initially identifying a cyber cause. County officials later described the incident as ransomware to local news outlets and discussed the investigation and recovery publicly. Because the cyber characterization came from affected-county officials, the incident supports organization-confirmed cyber transparency; the official alert and county officials’ service-impact statements support organization-documented disruption.

Current status

No source located for this assessment provides a final restoration notice or confirms the exact end of material impact. More than 30 days have elapsed since the May 19 vehicle-registration disruption, so the registry status is presumed resolved rather than resolved; the actual recovery date remains unknown.

Confidence and uncertainty

Confidence is high that ransomware caused the disruption because county officials explicitly identified ransomware and described the affected systems and response, with consistent corroboration from multiple local reports. Ransomware involvement is confirmed, but extortion is not: the available evidence documents no ransom demand, and no public actor claim was identified. Threat-actor attribution remains unresolved, and the evidence supports data unavailability but not data theft.

Analytic gaps

The public record does not establish the malware family, responsible actor, precise vulnerability, compromised account, dwell time, persistence, encryption scope, affected server count, exfiltration evidence, affected data categories, record count, ransom demand, payment activity, complete restoration sequence or final recovery date. The sanitation-computer account should be treated as a reported county assessment rather than a complete forensic conclusion.

Organizations involved

Impacted locations

Sources

Cyberattack disrupts Adams County, Mississippi, offices

DysruptionHub reported that Adams County officials identified an April 17 server crash as ransomware. The disruption blocked access to digital records and noncash payments, and the county approved more than $250,000 in emergency IT work; no ransom note, actor claim, data-theft finding or full-recovery confirmation was identified.

Adams County offices internet outage alert

The City of Natchez alerted residents that all Adams County offices were experiencing a countywide internet outage affecting multiple offices and services. It said City of Natchez services were not believed to be affected.

Ransomware attack cripples Adams County systems, officials say

WAPT reported that county officials said the April 17 ransomware attack locked employees out of court records, car-tag payments and public-records processing. Officials said about 70 percent of systems were back online, recovery was continuing, many records were backed up, and the breach’s full extent remained unknown.

Cyberattack Leaves Adams County Residents Unable to Renew Vehicle Tags

ListenUpYall reported that most county IT was back online but the tax collector still could not process vehicle-tax payments, car-tag renewals or new plates because the attack disabled the county’s connection to the Mississippi Department of Revenue. Officials said the investigation was ongoing and did not provide a restoration estimate for those services.

Adams County, Mississippi

Official profile information supporting the public description of Adams County.

Geographic profiles for selected U.S. locations

Official geographic reference used with local and state material to verify place names, jurisdiction types and location context for , adams, natchez.

See something that needs correction?

Signed-in members can report an error, update, or missing source.