Claim details
INCRansom listed the City of Cocoa as a victim; the city did not confirm the claim.
The City of Cocoa, Florida, reported technical problems affecting information technology systems beginning Feb. 16, 2026, disrupting phone service, payment handling and customer-service workflows. INCRansom listed Cocoa on its data-leak site Feb. 23, providing external cyber evidence, but the city did not publicly confirm ransomware or the group’s responsibility.
Only external sources publicly identify the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Internal or external network connectivity was unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The organization could not process, receive, issue, reconcile, or record payments normally.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
DysruptionHub assesses with high confidence that the City of Cocoa experienced a documented technology disruption and with medium confidence that the disruption was cyber-related. DysruptionHub’s reporting compiled the public operational record and the later actor claim. The city’s official update described technical issues affecting information technology systems beginning Feb. 16, 2026, but did not characterize the cause as cyber. Cyber-specific evidence appeared Feb. 23, when INCRansom listed the City of Cocoa on its leak site. The listing is a threat-actor claim, not confirmed attribution.
The disruption affected certain city systems, temporarily interrupted city telephone service, restricted cash payments for water bills and required some water-service and business-tax requests to be handled on paper or in person. Cocoa suspended delinquency processing and late fees while systems were impaired. Backup procedures kept services operating, and 911, emergency operations, dispatch, water-meter reading and several payment channels remained available. The City Council approved an emergency declaration Feb. 17 to speed emergency spending and resource deployment.
The affected municipality is Cocoa in Brevard County, Florida. The incident relationship is limited to Cocoa; the county is included only as the city’s administrative parent.
Confidence is high that the operational disruption occurred and medium that it involved ransomware because INCRansom’s leak-site post provides concrete external cyber evidence, but it does not prove that the group caused the outage, encrypted systems or stole city data. The city had not confirmed a cyberattack, ransomware, data theft, a ransom demand or attribution in the located public updates. Data impact and the technical mechanism remain unknown.
Cocoa first disclosed operational disruption and restoration work without cyber-specific language. The actor claim came later, and no later city cyber characterization was located, supporting external-only cyber transparency and organization-documented disruption.
The incident is presumed resolved because the last located operational update documented active restoration Feb. 23 and more than 30 days have elapsed without evidence of continuing disruption. Time alone does not establish full restoration, and no final closure notice was located.
The public record does not establish initial access, affected hosts, encryption, exfiltration, exposed data, ransom communications, payment, recovery cost, final restoration date or whether Cocoa validated or rejected INCRansom’s claim.
INCRansom listed the City of Cocoa as a victim; the city did not confirm the claim.

DysruptionHub reported that city IT problems disrupted payments and service requests while INCRansom listed Cocoa on its leak site; the city had not confirmed a cyberattack or ransomware.
Cocoa said technical issues affected certain IT systems beginning Feb. 16, that restoration was continuing and that the City Council approved an emergency declaration.
The INCRansom leak-site listing identified the City of Cocoa as a claimed victim. The listing is not independently verified and does not by itself establish encryption or data theft.
Signed-in members can report an error, update, or missing source.