Bowman Parks files encrypted in cyberattack
Summary
Bowman Parks & Recreation disclosed at a June 2, 2026, city commission meeting that a cyberattack encrypted every department file and connected thumb-drive backups, making the records inaccessible. The files were later decrypted with outside expert assistance, but the attack date, initial access method, ransom or payment status, data-copying scope and public-facing service impact remain unresolved.
Key facts
Timeline
-
First public signal:
?
Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity. -
First public cyber evidence:
?
Earliest credible public information connecting the incident or disruption to malicious cyber activity. -
Official cyber disclosure:
?
First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
Impacted locations
Primary victim organization
Organization types
Critical infrastructure sector
DysruptionHub coverage
Incident characteristics
Assessments
DD-CIT classification
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Attack mechanisms
-
Unknown cyber mechanism
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Data impacts
-
Data encryption
Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.
-
Backup compromise
Backup data or backup systems were accessed, encrypted, deleted, altered, disabled, or otherwise compromised.
-
Data unavailable
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Operational impacts
-
Internal systems unavailable
Internal business, administrative, operational, or staff-facing systems were unavailable.
-
Records access disruption
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
-
Staff unable to work normally
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
Extortion indicators
-
Unknown extortion indicators
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
Incident narrative
Analyst assessment
DysruptionHub assesses with high confidence that Bowman Parks & Recreation experienced malicious encryption of departmental data. DysruptionHub’s published report said Parks & Recreation Director Dan Peterson told the Bowman City Commission on June 2, 2026, that every department file had been encrypted and rendered inaccessible. Backup files stored on thumb drives connected to affected devices were also encrypted.
The available evidence is consistent with ransomware or another encryption-based extortion event, but it does not establish ransomware conclusively. Peterson said the department received a message from the attacker containing contact information for regaining access to the files. Public reporting did not establish that the message demanded money, that the city negotiated with the attacker or that any payment was made.
Operational significance
The confirmed disruption was the loss of staff access to internal parks department files. This affected the availability of departmental records, prevented staff from working with those records normally and defeated backups that remained connected to compromised devices. The public record does not identify the file categories involved or explain whether scheduling, facility operations, registrations, payroll, procurement or other functions depended on the encrypted records.
Peterson said the files were decrypted after he brought the problem to an expert in Bismarck. Reporting did not clarify whether the expert decrypted the original files, restored clean copies, used an available decryption tool or employed another recovery method. No public-facing service interruption was confirmed.
Disclosure posture
The incident became public through Peterson’s remarks at the June 2 city commission meeting and subsequent reporting by The Dickinson Press. DysruptionHub reported that Bowman Parks & Recreation did not respond to questions seeking the attack date, affected systems, restoration status, ransom or payment details, data-exposure information and any involvement by law enforcement or state cybersecurity officials.
Current status
The known operational impact is resolved. By the June 2 disclosure, Peterson said the affected files had already been decrypted with outside assistance. The exact recovery date is not public, and later searches found no continuing file-access problem or other parks-service disruption. Subsequent city discussion of cybersecurity investment and employee security measures reflects risk-reduction work, not evidence that this incident remained operationally active.
Confidence and uncertainty
Confidence is high that a cyberattack caused unauthorized file encryption because the parks director described the incident to the city commission and reported that every department file became inaccessible. Confidence that the incident was ransomware is medium: encryption, attacker contact instructions and recovery assistance are strongly suggestive, but no ransom demand, payment or malware identification was publicly documented.
Peterson said the attackers did not take the files. That statement is relevant but does not substitute for a published forensic assessment. The public record does not establish what technical evidence supported the conclusion that no files were copied.
Analytic gaps
The attack date, recovery date, initial access vector, affected devices, malware family, persistence, responsible actor and duration of unauthorized access are unknown. It is also unclear whether the attacker copied data, whether credentials were compromised, whether disconnected or offsite backups existed, whether law enforcement or state authorities were notified, and whether parks programs or public facilities experienced secondary effects.
Organizations involved
Bowman Parks & Recreation

Locations
Organization type
Critical infrastructure
Impacted locations
Sources
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
DysruptionHub reported that the Bowman parks director told the city commission every department file and connected thumb-drive backup had been encrypted and made inaccessible. The department received attacker contact instructions and later regained access with expert assistance, while ransom, payment, attack timing and public-facing impact remained unclear.
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
The Dickinson Press reported from the June 2 city commission meeting that Parks & Recreation Director Dan Peterson said a cyberattack encrypted every department file and connected backup drives. Peterson said the files were later decrypted after he sought expert assistance in Bismarck.