Analyst assessment
DysruptionHub’s published report said Boyne City was investigating a cybersecurity incident affecting limited portions of its computer network and digital systems. The city’s first located public acknowledgment was dated May 12 and described an incident the city identifies as occurring on May 11. Emergency and critical infrastructure reportedly remained unaffected, but later updates established sustained disruption to administrative and utility-billing functions.
DysruptionHub assesses with high confidence that the incident caused a material municipal technology and billing disruption. Local reporting documented limited computer functionality, disabled online payments, unavailable in-person utility payments, inaccessible account balances and payment history, delayed bills, and temporary suspension of late fees and shutoffs.
Operational significance
The documented effects centered on routine municipal administration rather than emergency response or critical infrastructure. Customers lost normal payment and account-history functions, and the city fell behind on quarterly utility billing.
In its July 31 recovery update, the city said the May billing cycle had been mailed July 29, the delayed June and July cycles were still being issued, and the August cycle would be later than usual. The online payment portal had returned, but staff were still restoring billing history, applying mailed payments that had been held during recovery, reviewing accounts, and working through customer questions.
Disclosure posture
Boyne City publicly acknowledged the cyber incident and later provided concrete utility-recovery information. Its statements consistently distinguished the administrative disruption from emergency and critical-infrastructure operations, which reportedly remained available.
The city has not publicly identified ransomware, a threat actor, a ransom demand, encryption or confirmed data theft. A later external report said The Gentlemen listed Boyne City on its leak site. DysruptionHub records that as an unverified actor claim rather than official attribution or proof that the listing concerns the same event.
Confidence and uncertainty
Confidence is high that the incident caused material disruption because the city and local reporting documented unavailable billing systems, disabled payment channels, delayed bills and continuing restoration work. Ransomware and attribution confidence remain low because the public record contains no city confirmation, forensic report, ransom note or technical evidence linking The Gentlemen to the May incident.
Data impact remains unresolved. The actor claim did not provide independently verified data types, record counts or affected-person totals, and the city has not confirmed that information was accessed, copied or published.
Current status
The latest reviewed city update showed substantial recovery but not a return to the normal billing schedule. Because restoration work was still documented on July 31 and the city expected August billing to remain delayed, DysruptionHub assesses the incident as active as of August 2, 2026.
Analytic gaps
The public record does not establish when malicious access began, the initial access vector, affected servers or accounts, dwell time, malware family, encryption scope, backup impact, ransom demand, payment status or whether the actor claim refers to the same event. It also does not identify confirmed data categories, record counts, affected individuals or a final restoration date.