Claim details
INCRansom listed the City of Cocoa Feb. 23, 2026. Cocoa later confirmed an external-system breach spanning Feb. 8-16 and notified 896 people, but it did not identify INCRansom or confirm ransomware, encryption or extortion.
Cocoa experienced an IT disruption after an external-system breach spanning February 8-16, 2026, disrupting phones, payments and municipal workflows while emergency and water operations continued. The city initially described the event only as “technical issues,” then notified 896 people of hacking June 4, 107 days after its first public operational disclosure and 101 days after INCRansom claimed the city. The claim remains unconfirmed, and some system restoration was still underway March 10.
External sources identified the event as cyber-related before the organization publicly confirmed it. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The organization could not process, receive, issue, reconcile, or record payments normally.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
Business, financial, customer, administrative, or operational transactions could not be completed normally.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
DysruptionHub assesses with high confidence that the City of Cocoa, Florida, experienced a cyber incident that disrupted municipal technology and compromised personal information. We reported that city IT problems affected services beginning Feb. 16 and that INCRansom listed Cocoa on its leak site Feb. 23. The city later reported an external-system breach spanning Feb. 8-16 in a Maine Attorney General filing.
The filing said 896 people were affected and that written notifications were sent June 4 with 12 months of Experian IdentityWorks offered. It corroborates hacking during the operational-disruption period but does not identify INCRansom, confirm ransomware or encryption, or establish that the claimant caused the breach.
The disruption interrupted city telephone service, restricted payment processing and required backup, paper and in-person workflows for water-service requests and business-tax receipts. Cocoa suspended delinquency processing and late fees. Emergency operations, dispatch and 911 continued, water meters remained readable and online, phone and check payment channels remained available.
An archived city update published from March 10-12 said phone service had been restored but certain systems still had technical issues and restoration remained underway. It continued to list restrictions on cash payments and some in-person or paper procedures.
Confidence is high that hacking affected city systems and personal information because Cocoa’s breach filing directly states that. The filing confirms unauthorized acquisition of personal information but does not identify the affected population or publicly establish every data category in the notification set. Ransomware and INCRansom attribution remain medium confidence because the claim is specific and temporally consistent but uncorroborated by the city.
Cocoa’s first public operational notice on Feb. 17 described only “technical issues,” even though the event had disrupted phones, payments and municipal workflows, required outside specialists and prompted an emergency declaration. INCRansom supplied the first public cyber-specific characterization Feb. 23. Cocoa did not acknowledge the incident’s cyber nature until its June 4 breach filing, 107 days after the first operational notice and 101 days after the external claim.
That is an unusually long disclosure gap for an incident whose operational severity was already plainly visible. The filing says Cocoa discovered the breach May 6, which may reflect when the forensic investigation established that hacking and personal-information compromise had occurred. The public record does not explain the full delay, however, and DysruptionHub does not infer concealment or another motive from the chronology alone.
The sequence supports an external-first, organization-confirmed DD-CIT assessment, or XC-OC, while Cocoa’s own operational notices support OD.
March 10 is the latest supported operational-impact date because the city said restoration continued for certain systems. The June breach notification is a later data-disclosure event and does not extend the service disruption. With more than 30 days since March 10 and no newer impact report, the incident is presumed resolved rather than confirmed resolved.
The public record does not establish initial access, compromised systems or accounts, malware, encryption, data-exfiltration method, the relationship between the breach and INCRansom, a ransom demand, payment, recovery cost, exact restoration date, the composition of the notification population or whether all compromised data belonged to one record category.
INCRansom listed the City of Cocoa Feb. 23, 2026. Cocoa later confirmed an external-system breach spanning Feb. 8-16 and notified 896 people, but it did not identify INCRansom or confirm ransomware, encryption or extortion.

We reported that city IT problems disrupted payments and service requests while INCRansom listed Cocoa on its leak site; the city had not confirmed a cyberattack or ransomware as of publication.
Cocoa said technical issues affected certain IT systems beginning Feb. 16, that restoration was continuing and that the City Council approved an emergency declaration.
The INCRansom leak-site listing identified the City of Cocoa as a claimed victim. The listing is not independently verified and does not by itself establish encryption or data theft.
Cocoa said phone systems had been restored but certain systems still had technical issues and restoration remained underway. The archived item was published from March 10 through March 12 and continued to list payment and service workarounds.
Cocoa reported an external-system breach spanning Feb. 8-16 that affected 896 people. The filing says the breach was discovered May 6, written notices were sent June 4 and 12 months of Experian IdentityWorks were offered.
Signed-in members can report an error, update, or missing source.