Skip to content

Bowman Parks files encrypted in cyberattack

Summary

Bowman Parks & Recreation disclosed at a June 2, 2026, city commission meeting that a cyberattack encrypted every department file and connected thumb-drive backups, making the records inaccessible. The files were later decrypted with outside expert assistance, but the attack date, initial access method, ransom or payment status, data-copying scope and public-facing service impact remain unresolved.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.

Impacted locations

Incident characteristics

Assessments

Status:
Resolved
Incident confidence:
High
Ransomware:
Medium

DD-CIT classification

OC-ODOfficial cyberOfficial disruptionAbout the DD-CIT methodology

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data encryption

    Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.

  • Backup compromise

    Backup data or backup systems were accessed, encrypted, deleted, altered, disabled, or otherwise compromised.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Bowman Parks & Recreation experienced malicious encryption of departmental data. DysruptionHub’s published report said Parks & Recreation Director Dan Peterson told the Bowman City Commission on June 2, 2026, that every department file had been encrypted and rendered inaccessible. Backup files stored on thumb drives connected to affected devices were also encrypted.

The available evidence is consistent with ransomware or another encryption-based extortion event, but it does not establish ransomware conclusively. Peterson said the department received a message from the attacker containing contact information for regaining access to the files. Public reporting did not establish that the message demanded money, that the city negotiated with the attacker or that any payment was made.

Operational significance

The confirmed disruption was the loss of staff access to internal parks department files. This affected the availability of departmental records, prevented staff from working with those records normally and defeated backups that remained connected to compromised devices. The public record does not identify the file categories involved or explain whether scheduling, facility operations, registrations, payroll, procurement or other functions depended on the encrypted records.

Peterson said the files were decrypted after he brought the problem to an expert in Bismarck. Reporting did not clarify whether the expert decrypted the original files, restored clean copies, used an available decryption tool or employed another recovery method. No public-facing service interruption was confirmed.

Disclosure posture

The incident became public through Peterson’s remarks at the June 2 city commission meeting and subsequent reporting by The Dickinson Press. DysruptionHub reported that Bowman Parks & Recreation did not respond to questions seeking the attack date, affected systems, restoration status, ransom or payment details, data-exposure information and any involvement by law enforcement or state cybersecurity officials.

Current status

The known operational impact is resolved. By the June 2 disclosure, Peterson said the affected files had already been decrypted with outside assistance. The exact recovery date is not public, and later searches found no continuing file-access problem or other parks-service disruption. Subsequent city discussion of cybersecurity investment and employee security measures reflects risk-reduction work, not evidence that this incident remained operationally active.

Confidence and uncertainty

Confidence is high that a cyberattack caused unauthorized file encryption because the parks director described the incident to the city commission and reported that every department file became inaccessible. Confidence that the incident was ransomware is medium: encryption, attacker contact instructions and recovery assistance are strongly suggestive, but no ransom demand, payment or malware identification was publicly documented.

Peterson said the attackers did not take the files. That statement is relevant but does not substitute for a published forensic assessment. The public record does not establish what technical evidence supported the conclusion that no files were copied.

Analytic gaps

The attack date, recovery date, initial access vector, affected devices, malware family, persistence, responsible actor and duration of unauthorized access are unknown. It is also unclear whether the attacker copied data, whether credentials were compromised, whether disconnected or offsite backups existed, whether law enforcement or state authorities were notified, and whether parks programs or public facilities experienced secondary effects.

Organizations involved

Impacted locations

Sources

Bowman, North Dakota parks files encrypted in cyberattack
DysruptionHubBy DysruptionHub StaffPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

DysruptionHub reported that the Bowman parks director told the city commission every department file and connected thumb-drive backup had been encrypted and made inaccessible. The department received attacker contact instructions and later regained access with expert assistance, while ransom, payment, attack timing and public-facing impact remained unclear.

Bowman City Commission confronts local cybersecurity weaknesses
The Dickinson PressBy Dorvall BedfordPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

The Dickinson Press reported from the June 2 city commission meeting that Parks & Recreation Director Dan Peterson said a cyberattack encrypted every department file and connected backup drives. Peterson said the files were later decrypted after he sought expert assistance in Bismarck.