Skip to content

City of Huntington Cybersecurity Incident

Summary

City of Huntington logo

Huntington, West Virginia, detected suspicious activity on February 17, 2026, and isolated municipal systems during a cybersecurity investigation. A limited number of internal systems were affected and normal operations returned February 19; Termite later claimed the city, but the listing remains uncorroborated.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that the City of Huntington, West Virginia, experienced a cybersecurity incident affecting a limited number of internal systems. The city’s official Facebook statement said monitoring detected suspicious activity on Feb. 17, 2026, systems were isolated and response protocols were activated. The city coordinated with the Cybersecurity and Infrastructure Security Agency and an outside cybersecurity provider to investigate, contain and remediate the incident. Our Feb. 18 report preserved the city’s statement and the initial uncertainty about service and data effects.

Termite listed the City of Huntington on March 7. The victim name, domain and timing are consistent with the known city incident, making the listing a stable claim rather than an unattributed rumor. It does not establish that Termite caused the intrusion, deployed ransomware, encrypted systems or possessed city data. RedPacket Security’s Termite archive also warns that listings attributed to the group have been reported as including unverified or fabricated victim claims.

Operational significance

A city representative said the incident affected a limited number of internal systems and that normal operations were restored by the morning of Feb. 19. The available public record does not identify a failed public-facing service, facility closure, resident workaround or emergency-service effect. The supported operational scope is therefore a short partial interruption involving internal municipal systems, not a citywide shutdown.

Confidence and uncertainty

Confidence is high that cyber activity occurred because the city expressly described suspicious activity and a cybersecurity incident. Confidence is also high that operational effects ended Feb. 19 because the city affirmatively reported restoration to normal operations. The continuing forensic review did not by itself indicate continuing service disruption.

Ransomware and Termite attribution remain low-confidence assessments. Termite’s listing is concrete external cyber evidence and is preserved as a claim, but Huntington has not publicly confirmed the group, a ransom demand, encryption or stolen data. No reviewed public data sample or incident-specific technical indicator corroborates the listing.

Disclosure posture

The city publicly disclosed the cybersecurity incident Feb. 18 and said its monitoring systems had detected the suspicious activity the previous night. Feb. 17 reflects the city’s internal detection date, while Feb. 18 is the earliest located public cyber signal. Huntington used cyber-specific language in its first located public statement and later documented the limited internal-system impact, supporting organization-first cyber and disruption transparency.

Current status

The operational disruption is resolved. Normal operations returned Feb. 19, two days after detection. The forensic review and later Termite listing do not extend the operational-impact period without evidence of continuing service degradation or restoration work.

Analytic gaps

The public record does not establish the initial access vector, whether an unauthorized party obtained access, the affected systems, compromised accounts or hosts, malware, persistence, encryption, exfiltration, affected data categories, ransom communications, payment, recovery method or incident-response cost. It also does not establish whether Huntington investigated, accepted or rejected Termite’s claim or whether the listing referred to this incident rather than another alleged event.

Threat actor and claim

Listed as: City of HuntingtonSource: ransomware.livePublished:

Claim details

Termite listed the City of Huntington and its cityofhuntington.com domain on March 7, 2026. The listing is a stable claim but remains uncorroborated by the city, an authenticated data sample or incident-specific technical evidence. RedPacket Security warns that listings attributed to Termite have been reported as including unverified or fabricated victim claims.

Organizations involved

Impacted location

Sources

Huntington, West Virginia addresses cybersecurity incident

We reported that Huntington detected suspicious activity, isolated systems and coordinated with CISA and an outside cybersecurity provider while assessing possible service and data effects.

Huntington officials investigating cybersecurity incident

WV MetroNews reported Feb. 18 that Huntington said it detected and responded to a cybersecurity incident the previous night, rapidly identified suspicious activity, activated response protocols and coordinated with CISA.

City of Huntington cybersecurity incident statement

Huntington said it detected and responded to a cybersecurity incident Tuesday night. Monitoring identified suspicious activity quickly, the city isolated systems and activated response protocols, and officials coordinated with CISA and an outside cybersecurity provider to investigate, contain and remediate the incident.

City of Huntington — Termite claim

Ransomware.live preserves a Termite leak-site listing naming the City of Huntington and cityofhuntington.com, dated March 7, 2026. The listing establishes a stable actor claim but does not by itself verify intrusion details, ransomware deployment, encryption, data theft or Termite responsibility.

Termite victim-listing verification warning

RedPacket Security’s Termite archive includes a City of Huntington entry dated March 7, 2026, and warns that listings attributed to Termite have been reported as including unverified or fabricated victim claims.

See something that needs correction?

Signed-in members can report an error, update, or missing source.