Skip to content

Boyne City cyber incident disrupts utility billing

Summary

City of Boyne City logo

Boyne City, Michigan experienced a cybersecurity incident on May 11, 2026, that disrupted municipal computer access, email, utility billing, online payments, and account-history functions. The city restored its online payment portal and resumed delayed billing by late July, while TheGentlemen later claimed the city on a ransomware leak site without official confirmation of attribution or data theft.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Payment processing disruption

    The organization could not process, receive, issue, reconcile, or record payments normally.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Backlog created

    The disruption caused an accumulation of unprocessed requests, cases, orders, records, appointments, or other work.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

DysruptionHub’s published report said Boyne City was investigating a cybersecurity incident affecting limited portions of its computer network and digital systems. The city’s first located public acknowledgment was dated May 12 and described an incident the city identifies as occurring on May 11. Emergency and critical infrastructure reportedly remained unaffected, but later updates established sustained disruption to administrative and utility-billing functions.

DysruptionHub assesses with high confidence that the incident caused a material municipal technology and billing disruption. Local reporting documented limited computer functionality, disabled online payments, unavailable in-person utility payments, inaccessible account balances and payment history, delayed bills, and temporary suspension of late fees and shutoffs.

Operational significance

The documented effects centered on routine municipal administration rather than emergency response or critical infrastructure. Customers lost normal payment and account-history functions, and the city fell behind on quarterly utility billing.

In its July 31 recovery update, the city said the May billing cycle had been mailed July 29, the delayed June and July cycles were still being issued, and the August cycle would be later than usual. The online payment portal had returned, but staff were still restoring billing history, applying mailed payments that had been held during recovery, reviewing accounts, and working through customer questions.

Disclosure posture

Boyne City publicly acknowledged the cyber incident and later provided concrete utility-recovery information. Its statements consistently distinguished the administrative disruption from emergency and critical-infrastructure operations, which reportedly remained available.

The city has not publicly identified ransomware, a threat actor, a ransom demand, encryption or confirmed data theft. A later external report said The Gentlemen listed Boyne City on its leak site. DysruptionHub records that as an unverified actor claim rather than official attribution or proof that the listing concerns the same event.

Confidence and uncertainty

Confidence is high that the incident caused material disruption because the city and local reporting documented unavailable billing systems, disabled payment channels, delayed bills and continuing restoration work. Ransomware and attribution confidence remain low because the public record contains no city confirmation, forensic report, ransom note or technical evidence linking The Gentlemen to the May incident.

Data impact remains unresolved. The actor claim did not provide independently verified data types, record counts or affected-person totals, and the city has not confirmed that information was accessed, copied or published.

Current status

The latest reviewed city update showed substantial recovery but not a return to the normal billing schedule. Because restoration work was still documented on July 31 and the city expected August billing to remain delayed, DysruptionHub assesses the incident as active as of August 2, 2026.

Analytic gaps

The public record does not establish when malicious access began, the initial access vector, affected servers or accounts, dwell time, malware family, encryption scope, backup impact, ransom demand, payment status or whether the actor claim refers to the same event. It also does not identify confirmed data categories, record counts, affected individuals or a final restoration date.

Threat actor and claim

Listed as: City of Boyne City, MichiganSource: otherPublished:

Claim details

TheGentlemen listed Boyne City on its leak site; the city has not confirmed attribution or data theft.

Organizations involved

Impacted location

Sources

Boyne City

Official state tourism profile describing Boyne City’s Lake Charlevoix setting and outdoor recreation.

2025 Gazetteer: Michigan Places

Official 2025 Census Gazetteer file identifying incorporated and census-designated places in Michigan.

Boyne City, Michigan, probes limited cybersecurity incident

Boyne City said a cybersecurity incident affected limited portions of its computer network and digital systems. Emergency and critical infrastructure were not affected while the city investigated the scope and secured systems.

Boyne City responds to cybersecurity incident affecting parts of city network

Boyne City said limited portions of its computer network and digital systems were affected, while emergency and critical infrastructure were not. Officials worked with IT and cybersecurity specialists to secure systems and investigate possible data compromise.

Boyne City disables online utility payments after cybersecurity incident

City systems operated with limited functionality. Online and in-person utility payments, account balances, and payment history were unavailable, May bills could be delayed, and the city suspended late fees and shutoffs during recovery.

Utility Billing Recovery Update

The city said the May billing cycle was mailed July 29, delayed June and July cycles were still being issued, and the August cycle would run late. The payment portal was restored, but staff continued restoring billing history, applying held mailed payments and reviewing accounts.

Boyne City, Michigan Claimed by TheGentlemen Ransomware

GalaxyWarden reported that TheGentlemen listed Boyne City on its leak site. The report did not identify a specific data volume, verified record types, affected-person count, or official city confirmation of the claim.

Boyne City, Michigan

The city portal lists commission and manager governance and municipal services including assessment, clerk and elections, police, fire, EMS, public works, water and wastewater, utility billing, parks, planning and zoning, an airport, a marina and transportation.

See something that needs correction?

Signed-in members can report an error, update, or missing source.