Anchorage Police Department

Anchorage Police Department shut down certain servers and disabled vendor access after learning Jan. 7, 2026, that a software provider involved in an upgrade had been attacked. APD found no evidence its systems were compromised or its data acquired.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Available evidence indicates that the incident did not materially affect the confidentiality, integrity, or availability of data.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
Our reporting confirms with high confidence that the Anchorage Police Department took containment measures in response to a confirmed cyberattack against third-party software provider White Box Technologies. The evidence does not establish that APD itself was compromised.
Municipal IT shut down relevant APD servers, disabled vendor and other third-party access, removed remaining APD data from the provider’s servers and alerted employees. APD did not report disruption to emergency response or public-safety services.
The impacted municipality is Anchorage, Alaska.
Confidence is high that a third-party cyberattack prompted APD containment because APD issued an official statement. Confidence is also high that no known APD compromise or data acquisition had been identified at disclosure, while the attack mechanism and vendor impact remain unknown.
APD disclosed the vendor cyber incident and its containment actions, supporting organization-confirmed cyber and disruption transparency.
The incident is presumed resolved because no continuing APD outage was located after containment, although no final closure notice was published.
The public record does not establish the vendor’s attack mechanism, actor, affected vendor systems, APD restoration date, forensic conclusion or whether later evidence changed the no-compromise finding.

We reported APD containment measures after a vendor attack and APD’s finding that its systems were not compromised.
APD said it shut down servers and third-party access after a provider attack and had no evidence of APD compromise or data acquisition.
Signed-in members can report an error, update, or missing source.