Analyst assessment
DysruptionHub assesses with high confidence that the City of Huntington, West Virginia, experienced a cybersecurity incident affecting a limited number of internal systems. The city’s official Facebook statement said monitoring detected suspicious activity on Feb. 17, 2026, systems were isolated and response protocols were activated. The city coordinated with the Cybersecurity and Infrastructure Security Agency and an outside cybersecurity provider to investigate, contain and remediate the incident. Our Feb. 18 report preserved the city’s statement and the initial uncertainty about service and data effects.
Termite listed the City of Huntington on March 7. The victim name, domain and timing are consistent with the known city incident, making the listing a stable claim rather than an unattributed rumor. It does not establish that Termite caused the intrusion, deployed ransomware, encrypted systems or possessed city data. RedPacket Security’s Termite archive also warns that listings attributed to the group have been reported as including unverified or fabricated victim claims.
Operational significance
A city representative said the incident affected a limited number of internal systems and that normal operations were restored by the morning of Feb. 19. The available public record does not identify a failed public-facing service, facility closure, resident workaround or emergency-service effect. The supported operational scope is therefore a short partial interruption involving internal municipal systems, not a citywide shutdown.
Confidence and uncertainty
Confidence is high that cyber activity occurred because the city expressly described suspicious activity and a cybersecurity incident. Confidence is also high that operational effects ended Feb. 19 because the city affirmatively reported restoration to normal operations. The continuing forensic review did not by itself indicate continuing service disruption.
Ransomware and Termite attribution remain low-confidence assessments. Termite’s listing is concrete external cyber evidence and is preserved as a claim, but Huntington has not publicly confirmed the group, a ransom demand, encryption or stolen data. No reviewed public data sample or incident-specific technical indicator corroborates the listing.
Disclosure posture
The city publicly disclosed the cybersecurity incident Feb. 18 and said its monitoring systems had detected the suspicious activity the previous night. Feb. 17 reflects the city’s internal detection date, while Feb. 18 is the earliest located public cyber signal. Huntington used cyber-specific language in its first located public statement and later documented the limited internal-system impact, supporting organization-first cyber and disruption transparency.
Current status
The operational disruption is resolved. Normal operations returned Feb. 19, two days after detection. The forensic review and later Termite listing do not extend the operational-impact period without evidence of continuing service degradation or restoration work.
Analytic gaps
The public record does not establish the initial access vector, whether an unauthorized party obtained access, the affected systems, compromised accounts or hosts, malware, persistence, encryption, exfiltration, affected data categories, ransom communications, payment, recovery method or incident-response cost. It also does not establish whether Huntington investigated, accepted or rejected Termite’s claim or whether the listing referred to this incident rather than another alleged event.