Skip to content

Beaver County behavioral health ransomware incident

Summary

Beaver County, Pennsylvania logo

Beaver County employees lost access to behavioral-health patient files during a ransomware incident later disclosed Aug. 4. Current service information and the absence of a later access problem support presumed operational resolution, while data and payment consequences remain open.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Incident characteristics

Assessments

DD-CIT assessment

External sources identified the event as cyber-related before the organization publicly confirmed it. Credible external sources document the disruption, but the organization does not clearly do so.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data encryption

    Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Encryption-based extortion

    The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Payment reported

    A source reported that the victim, insurer, intermediary, or another party made a ransom or extortion payment.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Beaver County, Pennsylvania, experienced a ransomware incident affecting computer systems used by Behavioral Health and Developmental Services. BeaverCountian’s Aug. 4 report said attackers stole and encrypted sensitive information, blocked employee access to patient files and threatened to publish medical records unless the county paid.

The evidence supports ransomware and double extortion but not attribution to a named operation. BeaverCountian described the actor only as a foreign hacker group. No public evidence connects this county-government incident to Interlock or to the separate March 2026 ransomware attack on the Community College of Beaver County.

Operational significance

The incident caused a documented loss of access to patient files used by county behavioral health employees. Beaver County’s BHDS page says the department supports mental health, intellectual disability, early intervention, and drug-and-alcohol services, making the affected records part of a public health and human-services function. Public reporting does not establish whether appointments, crisis services, eligibility decisions or other resident-facing services were delayed.

Current status

The incident is presumed resolved. The loss of employee access to behavioral-health files was reported retrospectively Aug. 4, and the county later paid a reported $175,000 ransom. The county’s current Behavioral Health page described services as accessible and continuously available when reviewed Aug. 31, and no later source reported that employees still lacked patient-file access or that service delivery remained impaired. This is an analytic presumption about operational recovery; it does not close the investigation, data-impact assessment or consequences of the payment.

Confidence and uncertainty

Confidence is high that malicious cyber activity, encryption, data theft, extortion and operational disruption occurred because the initial reporting described each element and a follow-up said the county solicitor publicly confirmed the original reporting. The first public cyber evidence is dated Aug. 4, but that publication date does not establish when attackers entered the environment, encrypted data or first disrupted employee access.

Confidence in ransomware involvement is high, while threat-actor attribution remains unresolved. The public record does not identify a ransomware family, cryptocurrency, wallet address, ransom-note details or stable leak-site claim attributable to this county-government incident.

Analytic gaps

The reviewed sources do not establish the intrusion date, initial access vector, compromised account or system, attacker dwell time, encryption scope, volume or categories of stolen data, number of affected people, duration of employee access loss, payment date, restoration method, decryptor outcome or final recovery date. They also do not establish whether systems outside Behavioral Health and Developmental Services were compromised or whether law enforcement or a federal cyber agency assisted.

Organizations involved

Impacted locations

Sources

Beaver County, Pennsylvania, pays $175,000 ransom after hackers cut access to patient files

Our reporting found that Beaver County commissioners paid a reported $175,000 ransom after attackers encrypted behavioral-health records and blocked employee access to patient files. The county solicitor publicly confirmed the original reporting, while the intrusion method, exact payment date, stolen-data details, named actor, decryptor outcome and full restoration remained unknown.

Hackers Successfully Blackmailed County Government For $175,000

A foreign hacker group took control of Beaver County government systems. Sensitive data was stolen and encrypted, leaving employees without patient-file access.

County Used Opioid Money To Pay Hacker's Ransom

Commissioners used opioid-settlement proceeds to buy cryptocurrency for the ransom; the county solicitor publicly confirmed the outlet’s original report at an Aug. 5 work session.

Our Senator Sponsored A Ransomware Ban – Then Our County Paid One

Beaver County commissioners paid hackers during August 2026 using public money, according to the outlet’s follow-up report.

Beaver County Behavioral Health service page

As reviewed Aug. 31, the county’s Behavioral Health page described its system of care as accessible and continuously available and did not identify a continuing cyber-related patient-file access problem or service limitation.

See something that needs correction?

Signed-in members can report an error, update, or missing source.