Chelan County, Washington

Chelan County, Washington shut down government networks, computers and telephone systems after detecting malware on May 24, 2026. Email, phones, records access and other county functions remained disrupted for weeks, and the Clerk’s Office later reported a backlog exceeding 6,000 documents as systems were restored.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malicious software other than ransomware used to compromise or disrupt systems.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
A primary service, system, platform, or operational capability became entirely unavailable.
Internal or external network connectivity was unavailable or materially impaired.
Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
The disruption caused an accumulation of unprocessed requests, cases, orders, records, appointments, or other work.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
DysruptionHub assesses with high confidence that Chelan County, Washington experienced a confirmed malware incident affecting its county government network beginning May 24, 2026. Chelan County’s department update said the county became aware of malware in its network environment and shut down the network while investigating the nature and scope of the event. DysruptionHub’s published report documented that computers and telephone systems were taken offline across county departments while 911 remained available.
The response was broader than isolation of a single device or application. Networks, computers and phones were shut down, and subsequent updates described an extended system-wide disruption affecting email, telephone service, Internet access and electronic records. The county worked with third-party security specialists and reported the incident to federal law enforcement.
The incident materially affected routine county business. Public reporting and county updates described unavailable phone and email systems, inaccessible records and temporary alternatives for contacting offices. Some departments established temporary telephone numbers and external email accounts.
The disruption also created substantial downstream delays. The county’s department update said the Clerk’s Office accumulated more than 6,000 documents while systems were unavailable and regained access to state document-management systems on June 22. The office estimated that processing the backlog could take about a month and warned of delays in responses to calls and email.
Emergency communications were not reported as fully unavailable. The initial county notice said 911 remained operational, which limits the supported public-safety impact. The record nevertheless establishes broad administrative disruption and prolonged impairment of normal government communication, records and processing channels.
Chelan County publicly acknowledged both the cyber cause and the operational consequences. Its statements identified malware, described the precautionary shutdown, explained that an investigation was underway and provided department-specific service updates. The disclosures did not identify the malware family, entry vector, affected hosts or whether data was accessed or removed.
Recovery occurred in stages. In a June 23 update, Chelan County said phones, employees’ desk computers and email had returned to workable conditions, offices were open and county websites had been back since June 15. It also said the county was still working to restore all systems, the deliberately cautious recovery was continuing and the investigation remained open.
The Clerk’s passport information page, updated July 8, still attributed a technology outage to the May 24 malware incident. It said the Clerk’s network had only begun recovering with state systems on June 22, passport appointments would reopen in the latter half of July and walk-in processing remained limited while staff caught up.
Because direct official evidence still documented incident-related service constraints on July 8, DysruptionHub assesses the incident as presumed active as of August 3, 2026. This status reflects continuing recovery, backlog and reduced service capacity; it does not mean malware was known to remain active in the environment.
Confidence is high that malware caused a material countywide disruption because the affected organization confirmed both the malicious software and the shutdown of county systems. Confidence is medium on the complete technical scope because no forensic report, final investigative finding or comprehensive restoration report has been published.
The public record does not confirm ransomware. It also contains no known extortion indicator: no ransom demand, extortion communication, leak-site claim or payment was identified. Data impact remains unresolved because the county’s updates do not establish whether information was accessed, copied, altered, deleted or exposed.
The public sources do not establish the initial access vector, vulnerability exploited, compromised account or device, malware family, dwell time, persistence method or number of affected systems. They also do not identify whether credentials were stolen, whether data was exfiltrated, whether backups were affected, or when every department returned to normal operations. A final all-clear, full restoration date and investigative conclusion were not found.

Official county guide describing Chelan County’s landscape, communities, resources and economy.
Official 2025 Census Gazetteer file identifying incorporated and census-designated places in Washington.
Official annual population estimates for incorporated places in the United States through July 1, 2024.
Official annual population estimates for counties and equivalent jurisdictions through July 1, 2024.
Official city history describing Wenatchee’s river confluence, mountain setting, county-seat role and agricultural development.
Chelan County shut down government networks, computers and phones across all departments after malware was detected. The county said 911 remained available while IT staff and security partners worked to restore systems.
Chelan County said it detected malware affecting its network environment on May 24 and shut down the network. Department updates last revised July 2 documented staged restoration, a Clerk’s Office backlog exceeding 6,000 documents, delayed calls and email, limited recording services and procurement work postponed because of the system-wide failure.
KPQ reported that Chelan County computer systems were expected to remain offline through at least the following week after the malware attack, confirming that restoration was still ongoing more than two weeks after detection.
Government Technology reported that the county shut down its network after detecting malware affecting computers and telephone systems across all departments, contracted a third-party security firm, and used temporary phone and email channels while the outage persisted.
Chelan County said phones, employee desk computers and email had returned to workable conditions, offices were open and websites had been restored, but the county was still working to restore all systems and the investigation remained ongoing.
In an announcement updated July 8, the Clerk said its network had suffered a technology outage from the May 24 malware incident and had only begun recovering with state systems on June 22. New passport appointments would open in the latter half of July, with limited walk-in processing while staff caught up.
The county portal and governmental organization chart identify elected commissioners, auditor, assessor, treasurer, sheriff, coroner, clerk, prosecutor and judges, together with departments including community development, public works, natural resources, emergency management, information technology, parks and solid waste.
Signed-in members can report an error, update, or missing source.