Analyst assessment
The City of Columbus, Ohio, detected a cyberattack on July 18, 2024, and severed internet connectivity to contain it, interrupting resident-facing technology services and internal operations. The city attributed the attack to Rhysida and said it prevented ransomware encryption, but attackers stole and published sensitive information. The city notified 500,000 people of potential exposure, according to BleepingComputer’s coverage of its breach filing. High confidence in the incident and attribution rests on city disclosures, the matching Rhysida claim and independent reporting; preventing encryption did not prevent disruption or data theft.
In its July 29 statement, the city corrected its initial explanation of access: investigators identified an internet website download rather than an email link. The city engaged the FBI, the Department of Homeland Security and outside cybersecurity experts. Rhysida’s July 31 victim claim alleged theft of 6.5 terabytes, including employee credentials, databases and emergency-service records. The Record reported that the group offered the data for 30 bitcoin and imposed a one-week deadline. The claimed volume and individual contents of that listing are not independently established in full.
Operational significance
The city’s July 19 outage post described disruption to internet-dependent services while 911 and 311 remained operational. Its July 22 cyber disclosure explicitly connected resident-facing outages to protective disconnection and also said payroll continued. External email was operating on city devices inside city buildings by July 29. These statements do not establish a citywide emergency-call outage, suspended payroll or a shutdown of every municipal service.
Recovery continued for months. The mayor’s Oct. 4 update reported that all critical IT systems were restored, but only 72% of 441 technology systems were fully restored and another 5% partially restored. The city’s 2024 financial report states that more than $7.3 million had been allocated by Dec. 31 for investigation, remediation, identity protection, legal counsel and security upgrades. That allocation is not a final loss estimate.
Data exposure extended across different municipal functions. The City Auditor’s September notice confirmed theft and publication of an unencrypted General Ledger backup containing 1999-2015 transactions; some vendors had used Social Security numbers as tax identifiers. The auditor said current income-tax, accounting and payroll systems were separate and had not been compromised. The Oct. 7 notification letter listed potentially affected names, dates of birth, addresses, bank account details, driver’s licenses, Social Security numbers and other information about interactions with the city. The 500,000-person total includes affected individuals, rather than establishing that every city resident or every listed data category was exposed.
On Feb. 3, 2025, the city disclosed that fewer than 1,000 people had protected health information in an affected Division of Fire dispatch database. The records could contain identity details and brief emergency medical service notes, with a small number of Social Security numbers. The city identified the health information on Dec. 12, 2024; it reported no evidence that the separate encrypted electronic medical record system was compromised. This was a later finding about the July attack, not a separate fire department intrusion.
Confidence and uncertainty
Cyber involvement, material service disruption, data theft and publication are established with high confidence by multiple city disclosures. Rhysida attribution is strongly supported by the city’s explicit Oct. 4 attribution and the matching victim claim. Ransomware-related extortion is confirmed, while successful encryption of city systems is not supported: the city expressly said it stopped encryption. The city’s corrected access account identifies a website download, and its subsequent notices establish that personal information was compromised.
July 18 is the supported detection and operational-start date; July 19 is the earliest verified public outage acknowledgment, and July 22 is the earliest verified cyber-specific disclosure. The actual intrusion may have begun earlier. Oct. 4 is the latest precisely dated continuing service-impact observation in the reviewed official updates; WOSU’s July 18, 2025 retrospective reports that some systems were not fully operational until 2025, without identifying the completion date.
Analytic gaps
The public record does not establish the exact initial intrusion date, full technical attack chain, final count of all exposed records, or the precise day every affected system returned to normal. Alleged stolen-data volumes should not be treated as audited totals. Exposure of health information does not establish compromise of the separate treatment-record system, and individual allegations of identity fraud do not establish that every later fraud event resulted from this attack.
Subsequent legal proceedings
An Ohio appeals court decision on Sept. 24, 2026, reversed the dismissal of consolidated complaints arising from the July 2024 attack and sent the cases back for further proceedings. The court assessed the allegations under the standard for a motion to dismiss; its decision did not establish that the city was negligent or determine damages. The litigation does not indicate renewed service disruption.
Current status
Operationally resolved. City spokeswoman Jennifer Fening confirmed that city IT systems had been restored in WOSU’s July 14, 2025 report. The report also described a $23 million security investment; continuing litigation, forensic review and security improvements are separate from continuing service disruption. The evidence supports restoration by that date, but not an exact completion date.