Beaver County, Pennsylvania

Beaver County employees lost access to behavioral-health patient files during a ransomware incident later disclosed Aug. 4. Current service information and the absence of a later access problem support presumed operational resolution, while data and payment consequences remain open.
External sources identified the event as cyber-related before the organization publicly confirmed it. Credible external sources document the disruption, but the organization does not clearly do so.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.
The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.
The actor explicitly threatened to publish or publicly release victim data or incident details.
A source reported that the victim, insurer, intermediary, or another party made a ransom or extortion payment.
DysruptionHub assesses with high confidence that Beaver County, Pennsylvania, experienced a ransomware incident affecting computer systems used by Behavioral Health and Developmental Services. BeaverCountian’s Aug. 4 report said attackers stole and encrypted sensitive information, blocked employee access to patient files and threatened to publish medical records unless the county paid.
The evidence supports ransomware and double extortion but not attribution to a named operation. BeaverCountian described the actor only as a foreign hacker group. No public evidence connects this county-government incident to Interlock or to the separate March 2026 ransomware attack on the Community College of Beaver County.
The incident caused a documented loss of access to patient files used by county behavioral health employees. Beaver County’s BHDS page says the department supports mental health, intellectual disability, early intervention, and drug-and-alcohol services, making the affected records part of a public health and human-services function. Public reporting does not establish whether appointments, crisis services, eligibility decisions or other resident-facing services were delayed.
The incident is presumed resolved. The loss of employee access to behavioral-health files was reported retrospectively Aug. 4, and the county later paid a reported $175,000 ransom. The county’s current Behavioral Health page described services as accessible and continuously available when reviewed Aug. 31, and no later source reported that employees still lacked patient-file access or that service delivery remained impaired. This is an analytic presumption about operational recovery; it does not close the investigation, data-impact assessment or consequences of the payment.
Confidence is high that malicious cyber activity, encryption, data theft, extortion and operational disruption occurred because the initial reporting described each element and a follow-up said the county solicitor publicly confirmed the original reporting. The first public cyber evidence is dated Aug. 4, but that publication date does not establish when attackers entered the environment, encrypted data or first disrupted employee access.
Confidence in ransomware involvement is high, while threat-actor attribution remains unresolved. The public record does not identify a ransomware family, cryptocurrency, wallet address, ransom-note details or stable leak-site claim attributable to this county-government incident.
The reviewed sources do not establish the intrusion date, initial access vector, compromised account or system, attacker dwell time, encryption scope, volume or categories of stolen data, number of affected people, duration of employee access loss, payment date, restoration method, decryptor outcome or final recovery date. They also do not establish whether systems outside Behavioral Health and Developmental Services were compromised or whether law enforcement or a federal cyber agency assisted.

Our reporting found that Beaver County commissioners paid a reported $175,000 ransom after attackers encrypted behavioral-health records and blocked employee access to patient files. The county solicitor publicly confirmed the original reporting, while the intrusion method, exact payment date, stolen-data details, named actor, decryptor outcome and full restoration remained unknown.
A foreign hacker group took control of Beaver County government systems. Sensitive data was stolen and encrypted, leaving employees without patient-file access.
Commissioners used opioid-settlement proceeds to buy cryptocurrency for the ransom; the county solicitor publicly confirmed the outlet’s original report at an Aug. 5 work session.
Beaver County commissioners paid hackers during August 2026 using public money, according to the outlet’s follow-up report.
As reviewed Aug. 31, the county’s Behavioral Health page described its system of care as accessible and continuously available and did not identify a continuing cyber-related patient-file access problem or service limitation.
Signed-in members can report an error, update, or missing source.