Skip to content

Cocoa IT disruption, data breach and INCRansom claim

Summary

City of Cocoa logo

Cocoa experienced an IT disruption after an external-system breach spanning February 8-16, 2026, disrupting phones, payments and municipal workflows while emergency and water operations continued. The city initially described the event only as “technical issues,” then notified 896 people of hacking June 4, 107 days after its first public operational disclosure and 101 days after INCRansom claimed the city. The claim remains unconfirmed, and some system restoration was still underway March 10.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

External sources identified the event as cyber-related before the organization publicly confirmed it. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

Operational impacts

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that the City of Cocoa, Florida, experienced a cyber incident that disrupted municipal technology and compromised personal information. We reported that city IT problems affected services beginning Feb. 16 and that INCRansom listed Cocoa on its leak site Feb. 23. The city later reported an external-system breach spanning Feb. 8-16 in a Maine Attorney General filing.

The filing said 896 people were affected and that written notifications were sent June 4 with 12 months of Experian IdentityWorks offered. It corroborates hacking during the operational-disruption period but does not identify INCRansom, confirm ransomware or encryption, or establish that the claimant caused the breach.

Operational significance

The disruption interrupted city telephone service, restricted payment processing and required backup, paper and in-person workflows for water-service requests and business-tax receipts. Cocoa suspended delinquency processing and late fees. Emergency operations, dispatch and 911 continued, water meters remained readable and online, phone and check payment channels remained available.

An archived city update published from March 10-12 said phone service had been restored but certain systems still had technical issues and restoration remained underway. It continued to list restrictions on cash payments and some in-person or paper procedures.

Confidence and uncertainty

Confidence is high that hacking affected city systems and personal information because Cocoa’s breach filing directly states that. The filing confirms unauthorized acquisition of personal information but does not identify the affected population or publicly establish every data category in the notification set. Ransomware and INCRansom attribution remain medium confidence because the claim is specific and temporally consistent but uncorroborated by the city.

Disclosure posture

Cocoa’s first public operational notice on Feb. 17 described only “technical issues,” even though the event had disrupted phones, payments and municipal workflows, required outside specialists and prompted an emergency declaration. INCRansom supplied the first public cyber-specific characterization Feb. 23. Cocoa did not acknowledge the incident’s cyber nature until its June 4 breach filing, 107 days after the first operational notice and 101 days after the external claim.

That is an unusually long disclosure gap for an incident whose operational severity was already plainly visible. The filing says Cocoa discovered the breach May 6, which may reflect when the forensic investigation established that hacking and personal-information compromise had occurred. The public record does not explain the full delay, however, and DysruptionHub does not infer concealment or another motive from the chronology alone.

The sequence supports an external-first, organization-confirmed DD-CIT assessment, or XC-OC, while Cocoa’s own operational notices support OD.

Current status

March 10 is the latest supported operational-impact date because the city said restoration continued for certain systems. The June breach notification is a later data-disclosure event and does not extend the service disruption. With more than 30 days since March 10 and no newer impact report, the incident is presumed resolved rather than confirmed resolved.

Analytic gaps

The public record does not establish initial access, compromised systems or accounts, malware, encryption, data-exfiltration method, the relationship between the breach and INCRansom, a ransom demand, payment, recovery cost, exact restoration date, the composition of the notification population or whether all compromised data belonged to one record category.

Threat actor and claim

Listed as: The City of CocoaSource: ransomware.livePublished:

Claim details

INCRansom listed the City of Cocoa Feb. 23, 2026. Cocoa later confirmed an external-system breach spanning Feb. 8-16 and notified 896 people, but it did not identify INCRansom or confirm ransomware, encryption or extortion.

Organizations involved

Impacted location

Sources

Cocoa, Florida faces possible ransomware hit as city IT systems falter

We reported that city IT problems disrupted payments and service requests while INCRansom listed Cocoa on its leak site; the city had not confirmed a cyberattack or ransomware as of publication.

Ongoing Technical Issues

Cocoa said technical issues affected certain IT systems beginning Feb. 16, that restoration was continuing and that the City Council approved an emergency declaration.

The City of Cocoa — INCRansom claim

The INCRansom leak-site listing identified the City of Cocoa as a claimed victim. The listing is not independently verified and does not by itself establish encryption or data theft.

Ongoing Technical Issues

Cocoa said phone systems had been restored but certain systems still had technical issues and restoration remained underway. The archived item was published from March 10 through March 12 and continued to list payment and service workarounds.

City of Cocoa, FL data breach notice

Cocoa reported an external-system breach spanning Feb. 8-16 that affected 896 people. The filing says the breach was discovered May 6, written notices were sent June 4 and 12 months of Experian IdentityWorks were offered.

See something that needs correction?

Signed-in members can report an error, update, or missing source.