Adams County

A ransomware attack that Adams County officials said began April 17, 2026, disrupted county networks, digital court and public records, vehicle registration, and noncash payments while the sheriff’s separate systems remained available. Most county IT was restored by early May, but vehicle-tag services were still unavailable on May 19; no ransom demand, data-theft finding, responsible actor or final restoration date was publicly established.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
The organization lost or materially restricted internet connectivity.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The organization could not process, receive, issue, reconcile, or record payments normally.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
County officials told local media that an April 17 server crash was identified as ransomware, and Supervisor Kevin Wilson said the FBI confirmed an attack and was investigating. Our April 29 report documented those statements, the countywide outage, the absence of a ransom note and the lack of any public ransomware-group claim. Separately, DysruptionHub assesses with high confidence that malicious cyber activity caused a material county-government disruption.
The reported entry point was a sanitation department computer running Windows 7, after which the compromise spread through the county network. That account came from county IT Director Devonte Demby, but the available public record does not provide forensic findings, a malware family, an exploited vulnerability, persistence details or independent technical confirmation of the initial-access path. The record also does not establish whether information was accessed or removed.
The incident prevented employees from accessing digital civil and circuit-court records and disrupted public-records processing, vehicle-tag payments and other online county business. Offices used cash-only payment workarounds while normal electronic services were unavailable, and the county approved more than $250,000 in emergency network, equipment, monitoring and data-recovery work. The sheriff’s office remained operational because it used servers separate from the affected county environment.
By May 1, officials said about 70% of systems were back online and recovery was continuing. On May 19, the tax collector still could not process vehicle taxes, renew car tags or issue plates because the attack had disabled the county’s connection to the Mississippi Department of Revenue. This continuing public-service effect supports May 19 as the latest documented impact date.
The City of Natchez publicly alerted residents to a countywide internet outage on April 20 without initially identifying a cyber cause. County officials later described the incident as ransomware to local news outlets and discussed the investigation and recovery publicly. Because the cyber characterization came from affected-county officials, the incident supports organization-confirmed cyber transparency; the official alert and county officials’ service-impact statements support organization-documented disruption.
No source located for this assessment provides a final restoration notice or confirms the exact end of material impact. More than 30 days have elapsed since the May 19 vehicle-registration disruption, so the registry status is presumed resolved rather than resolved; the actual recovery date remains unknown.
Confidence is high that ransomware caused the disruption because county officials explicitly identified ransomware and described the affected systems and response, with consistent corroboration from multiple local reports. Ransomware involvement is confirmed, but extortion is not: the available evidence documents no ransom demand, and no public actor claim was identified. Threat-actor attribution remains unresolved, and the evidence supports data unavailability but not data theft.
The public record does not establish the malware family, responsible actor, precise vulnerability, compromised account, dwell time, persistence, encryption scope, affected server count, exfiltration evidence, affected data categories, record count, ransom demand, payment activity, complete restoration sequence or final recovery date. The sanitation-computer account should be treated as a reported county assessment rather than a complete forensic conclusion.

The victim is the county government and the disruption affected county offices and county-administered services.
DysruptionHub reported that Adams County officials identified an April 17 server crash as ransomware. The disruption blocked access to digital records and noncash payments, and the county approved more than $250,000 in emergency IT work; no ransom note, actor claim, data-theft finding or full-recovery confirmation was identified.
The City of Natchez alerted residents that all Adams County offices were experiencing a countywide internet outage affecting multiple offices and services. It said City of Natchez services were not believed to be affected.
WAPT reported that county officials said the April 17 ransomware attack locked employees out of court records, car-tag payments and public-records processing. Officials said about 70 percent of systems were back online, recovery was continuing, many records were backed up, and the breach’s full extent remained unknown.
ListenUpYall reported that most county IT was back online but the tax collector still could not process vehicle-tax payments, car-tag renewals or new plates because the attack disabled the county’s connection to the Mississippi Department of Revenue. Officials said the investigation was ongoing and did not provide a restoration estimate for those services.
Official profile information supporting the public description of Adams County.
Official geographic reference used with local and state material to verify place names, jurisdiction types and location context for , adams, natchez.
Signed-in members can report an error, update, or missing source.