City of Attleboro

The City of Attleboro, Massachusetts, detected suspicious network activity on Nov. 20, 2025, and took systems offline, disrupting municipal email, most phone lines and routine City Hall work. Emergency response and public schools remained operational; municipal phone and email service was later restored, but the city had not issued a final investigative or data-impact finding as of September 2026.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Services continued but with longer processing, response, delivery, or completion times.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
DysruptionHub assesses with high confidence that the City of Attleboro experienced a cyber incident in November 2025. The city said on Nov. 20 that a cybersecurity incident had taken several information technology systems offline. Its subsequent FAQ said officials detected suspicious network activity on or about Nov. 20 and immediately disconnected affected systems. The public record does not establish when the underlying activity began or whether the disruption resulted from the activity itself, containment measures, or both.
The initial city notice said internal email was unavailable across departments and nearly all municipal and police phone lines were out of service. City Hall remained open, but staff used paper forms and accepted offline bill and tax payments. Officials warned that some tasks would be delayed while employees used temporary procedures.
The city said 911, public-safety radio systems and police and fire business lines continued working. Dispatchers made manual adjustments, but police and fire continued emergency response, and mutual-aid communications remained available. Attleboro Public Schools were not affected. The disruption therefore centered on municipal administration and routine public contact rather than a documented interruption to emergency response or instruction.
Attleboro publicly identified the event as a cybersecurity incident in its Nov. 20 statement. Mayor Cathleen DeSimone later described continuing restoration work and said outside specialists were helping city IT staff investigate the scope and strengthen defenses. The city did not identify a specific intrusion method or actor in those statements.
A city FAQ said all phone lines were operational, but did not give a restoration date. The city’s March 17 capital improvements plan labeled a proposed $100,000 firewall expansion and redundancy project for fiscal 2027 as urgent following the cyber incident. It also described a phased cybersecurity infrastructure overhaul for fiscal 2027-2029 as a direct result of the incident; its cost was not yet determined. These are planned security investments, not a reported cost of restoring affected services.
In a March 30, 2026, update, the city said the incident had been quickly contained and posed no ongoing threat to city systems. Its forensic investigation remained underway. Mayor DeSimone told The Sun Chronicle in July that the city’s insurance covered outside forensic, public-relations and legal services, and that it had increased its cyber-insurance coverage from $1 million to $3 million effective July 1. Those policy limits do not establish the cost of the incident.
The Sun Chronicle reported Sept. 24 that municipal phone and email service had been restored. The mayor told the newspaper Sept. 22 that the investigation remained open and she hoped to have a final report soon. The available statements support an end to the acute communications disruption but do not establish precisely when every affected service returned or provide a system-by-system all-clear.
The city’s fiscal 2027 proposed budget adds administrative recovery detail. The auditor’s fiscal 2026 accomplishments describe rebuilding information as needed after the cyber incident, while meeting required federal audit-report and financial-statement deadlines. The incident delayed a plan to decentralize the warrant process, carried forward as a fiscal 2027 objective. The document does not establish that records were permanently destroyed or specify when this work occurred.
The budget also lists security improvements implemented after the November attack: modernized cloud infrastructure, stronger email security, multifactor authentication, and endpoint and managed threat detection and response. Proposed fiscal 2027 subscription funding would sustain products procured after the attack. The proposed funding is not a verified total incident cost or evidence of renewed service disruption.
Confidence is high that a cyber incident and operational disruption occurred because the city directly documented suspicious network activity, system shutdowns and service effects. The Sun Chronicle reported that Police Chief Kyle Heagney said early in the investigation that ransomware was possible. The city has not confirmed encryption or a ransom demand, and searches for the city name and domain found no stable ransomware or extortion victim claim. Ransomware and threat-actor attribution remain unresolved.
Data exposure also remains unresolved. Heagney said early in the investigation that officials had found no evidence resident data was stolen or transferred, according to The Sun Chronicle. That preliminary finding does not settle the outcome: the city said in March it was reviewing information that may have been involved and would notify individuals if needed, and the mayor said the investigation was still open in September. No final public data-impact finding has been identified.
The public record does not identify the initial access vector, affected account or host, malware, attacker dwell time, data categories, number of affected people or a responsible group. It does not establish the restoration date for email or other affected systems, or provide a final forensic finding on personal information.

We reported that municipal phone lines and internal email were offline, forcing paper workarounds, while emergency response continued and Attleboro Public Schools were unaffected.
The city and police department were investigating a cybersecurity incident that took several IT systems offline. Citywide employee email and most city and police phone lines were unavailable; City Hall used paper forms and offline payments, while 911, public-safety radio, police and fire response continued.
WPRI reported Dec. 10 that the city continued dealing with the cybersecurity incident and that the mayor posted an update describing added security measures, heightened monitoring and third-party specialists.
The city’s March 17, 2026, capital plan elevated a proposed fiscal 2027 firewall project to urgent priority after the FY2026 cyber incident, with an estimated $100,000 cost. It identified a separate phased FY2027-2029 cybersecurity restructuring as a direct result of the incident; cost TBD.
The city said it detected suspicious network activity in November, immediately took affected systems offline, and quickly contained the incident. It said there was no ongoing threat to city systems, but the forensic investigation and review of potentially involved information remained underway.
The newspaper reported that Attleboro municipal phone and email service had been restored. Mayor Cathleen DeSimone said Sept. 22, 2026, the incident remained under investigation and she hoped for a final report soon. The report also recounted Police Chief Kyle Heagney’s preliminary statement that ransomware was possible and investigators then had no evidence resident data was stolen or transferred; the mayor said in July insurance covered outside forensic, PR and legal services and the city increased cyber-insurance coverage to $3 million.
Mayor Cathleen DeSimone described a disruptive cybersecurity incident requiring certain city systems to be taken offline. She said third-party cybersecurity specialists and city IT staff were investigating and helping restore systems safely.
The city said suspicious network activity was detected on or about Nov. 20, 2025, and affected systems were immediately taken offline. It said all phone lines were operational when the FAQ was issued, but the scope of any affected personal information was not known.
Fiscal2026 accomplishments list security controls implemented after the November2025 attack. Auditor’s office rebuilt information as needed and met federal audit/financial-statement deadlines; incident delayed warrant-process decentralization. Fiscal2027subscriptionfunding proposed to sustain newlyprocuredcyberproducts.
Signed-in members can report an error, update, or missing source.