Skip to content

Fort Smith network security event disrupts city services

Summary

City of Fort Smith logo

Fort Smith confirmed data theft, publication and a ransom demand. Public-facing services returned, but employees still lacked shared-file access Sept. 24; Interlock attribution remains unconfirmed.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data publication or leak

    Stolen, exposed, or otherwise compromised data was publicly released, posted, distributed, or offered for download.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Payment processing disruption

    The organization could not process, receive, issue, reconcile, or record payments normally.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Payment denied

    An authoritative source stated that no ransom or extortion payment was made.

Incident narrative

Analyst assessment

Fort Smith disclosed Aug. 16 a network security event that disrupted municipal systems and services. In a Sept. 15 update, City Administrator Jeff Dingman confirmed that an unauthorized actor entered city systems through the Police Department and exfiltrated data. The city said the threat had been contained and additional systems were still being restored.

The city’s Sept. 23 statement, reproduced by Talk Business & Politics, confirmed that a portion of city data had been taken and subsequently released. It said current financial, accounting, customer-data and human-resources systems were not involved and that it had found no evidence customer or resident credit-card or banking information was compromised. Those findings do not exclude other categories of stolen information; review and potential notification work continued.

In a Sept. 24 interview with 5NEWS, Dingman confirmed a ransom demand and said the city neither negotiated nor paid. He said the entry point had been addressed and the attacker had remained detectable for weeks, until approximately a week and a half to two weeks before the interview. He did not identify the access method or confirm encryption.

Operational significance

The initial disruption affected city computer systems and services. KNWA/KFTA reported Aug. 17 that card readers at city offices and the landfill Scale House were unavailable, requiring cash or checks.

The city reported Sept. 15 that payment systems at City Hall, District Court and the landfill had returned and all public-facing city services were online. Its Sept. 16 utility-payment reminder said third-party online utility-payment systems had not been affected.

Public-facing restoration was not complete internal recovery. In the Sept. 24 interview, Dingman said some employees still could not access files previously stored on shared network drives. This establishes continuing internal file-access disruption.

The city said 911 dispatch and emergency response remained functional. No reviewed source establishes interruption to emergency response, water or wastewater operations or transit. Alleged theft of information about those services does not establish an operational outage.

Disclosure posture

The Aug. 16 announcement supplied the earliest identified public cyber-specific characterization and operational disclosure. Subsequent statements established unauthorized access, exfiltration, publication and a ransom demand. The city said disclosure remained limited while investigation, data review and security work continued.

Current status

The incident is active because the Sept. 24 interview documents continuing employee file-access restrictions. The latest supported impact observation is Sept. 24; no full recovery date is established. This replaces the earlier presumed-resolved assessment, which was based on ordinary public service channels before the newer internal-impact disclosure was reviewed.

Dingman described data review as a work in progress without a firm completion timeline. Containment, restored public services and an available city website do not establish restoration of every internal system.

Confidence and uncertainty

Confidence is high in unauthorized access, data theft and publication, a ransom demand, payment denial and continuing internal file-access disruption because the city or its named administrator confirmed them.

An Interlock claim recorded by ransomware.live names the city and its domain. The previously captured Interlock-branded page alleged 5,720 GB, millions of files, law-enforcement records, Social Security numbers, mobile-device records, water-system information and 911 data. These categories and quantities remain claims, not authenticated findings. Dingman did not confirm the group’s roughly 5.7-terabyte figure and described a possible one-to-two-terabyte amount as an uncertain impression. Neither estimate is treated as a verified total.

Interlock attribution and ransomware involvement remain low-confidence assessments. Confirmation of theft and a ransom demand does not establish the attacker’s identity or encryption. A subscriber-limited expert report’s accessible introduction distinguishes possession of data from responsibility for the intrusion; its inaccessible reasoning was not used to upgrade attribution.

Analytic gaps

Unresolved issues include the exact access vector, malware or encryption, complete affected-system inventory, verified data volume and categories, affected-person count, notification findings, attacker identity and full technical recovery date. No stolen files were downloaded or independently authenticated.

Threat actor and claim

Listed as: City of Fort Smith ArkansasSource: ransomware.liveDiscovered:

Claim details

Interlock’s branded leak page names the City of Fort Smith and fortsmithar.gov and claims a 5,720 GB collection containing 4,882,956 files and 326,671 folders. It alleges law-enforcement data, more than 100,000 Social Security numbers, police records, mobile-device records, water-system information and 911 call data. The screenshot documents the claim but does not establish the files’ authenticity or provenance. The city subsequently confirmed data theft and publication and a ransom demand, but has not confirmed encryption or Interlock’s involvement. The claimed categories, quantities and provenance remain unverified.

Organizations involved

Impacted location

Sources

Network security event disrupts Fort Smith, Arkansas, city services

We reported that a network security event disrupted certain city computer systems and services; 911 dispatch and emergency response remained fully functional, and no full restoration had been announced by Monday morning.

City of Fort Smith Responding to Network Security Event

The city said a security event affected its computer network and disrupted certain computer systems and city services. It said 911 dispatch and emergency-services response remained fully functional while restoration work continued with government partners, federal law enforcement and cybersecurity specialists.

Latest News | Fort Smith experiencing 'network security' issue

The outlet reported that the City of Fort Smith had identified a security event affecting its computer network on Sunday, Aug. 16.

Fort Smith services down due to “network security event,” city says

KNWA/KFTA reported that Fort Smith still had network issues Aug. 17. Card readers at city offices and the landfill Scale House were offline, requiring cash or checks, while the city said updates would follow when systems returned online.

City Administrator Jeff Dingman Provides Update on Cybersecurity Event

Primary release confirms unauthorized entry through police department, exfiltration, restored public-facing services and continuing additional-system restoration.

Reminder: Online Utility Bill Payment Available to Residents

Third-party online utility-payment systems were not affected; distinguishes them from city-office card readers.

Information & Technology

The city says its information technology department supports municipal telecommunications, servers, computers, software, network, website, intranet and e-government services.

City of Fort Smith official website

The organization’s official website describes its identity, services, operating role and public or customer-facing programs.

Gazetteer Files

The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.

Fort Smith resident service page

As reviewed Aug. 31, the city service page directed residents to ordinary online and telephone channels for water, sewer and solid-waste service and did not identify a continuing cyber-related payment restriction or workaround.

See something that needs correction?

Signed-in members can report an error, update, or missing source.