Claim details
DragonForce claimed the city as a victim; the city has not verified responsibility or the group’s asserted data volume.
The City of La Vergne disclosed a network compromise in October 2025 that closed public offices, took systems offline and limited library services for weeks. The city later sent breach notifications, while a DragonForce extortion claim remains unverified.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Data was made accessible to unauthorized parties through misconfiguration, system compromise, improper access controls, or another unintended condition.
Internal or external network connectivity was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
DysruptionHub assesses with high confidence that the City of La Vergne experienced a cyber incident that disrupted municipal computer systems in October 2025. The city reported on Oct. 17 that it had taken affected systems offline, engaged cybersecurity specialists and law enforcement, and kept public safety and water services operating. Its Oct. 20 update described a compromise of the city network and said unusual activity had been detected on the morning of Oct. 17. That is the first established detection date, not proof of when unauthorized activity began.
The DragonForce listing names the city as a claimed victim. Comparitech reported that the group alleged it had stolen 382 gigabytes of data and threatened release. The city has not publicly verified the group’s responsibility, the claimed quantity or the use of ransomware. The listing supports an extortion claim, not confirmed encryption or attribution.
The city said its offices closed to the public and employees were sent home early while the network was offline. Managers used manual processes to keep work going, according to the Oct. 20 city update. By Oct. 29, City Hall and City Court were preparing to resume regular hours with limited functions, the public library remained closed, and city meetings could not be livestreamed.
The library reopened with limited services on Nov. 13, but books could not be checked out and public computers were unavailable. This shows that disruption to a resident-facing service lasted at least into mid-November. The city’s initial statement said essential public safety and water services remained operational; the reviewed sources do not establish interruption of emergency response or water delivery.
The city’s early public notices described the network disruption and service limitations. In June 2026, the city confirmed that it had sent legitimate notification letters to people who might have been affected by the October incident. A Massachusetts breach report lists 14 residents affected and Social Security numbers breached; a Vermont attorney general listing also identifies Social Security numbers for one resident. Those records substantiate a personal-information impact for notified people, but do not establish how the information was obtained, whether it was exfiltrated, or whether DragonForce possessed it.
The last reviewed city notice showing an operational limitation was the Nov. 13 library update. Because that notice is nearly a year old and no final restoration statement was found, DysruptionHub assesses that the operational disruption is presumed resolved while the precise recovery date remains unknown. The 2026 notification process is a later consequence of the incident, not evidence that city systems remained disrupted then.
Confidence is high that a cyber-related network compromise occurred and affected city services because the city directly documented both. Confidence is high that notification involved Social Security numbers for at least some recipients because state breach records identify that data category. Confidence is low in DragonForce attribution and its claimed data volume: the group made the allegation, but independent public verification was not found. Ransomware encryption remains unestablished.
The reviewed record does not establish initial access, the specific attack mechanism, malware, the full set of affected systems, when unauthorized activity began, the total number of people affected, the scope of any data transfer, the ransom demand or payment status, or the date all municipal and library functions were restored.
DragonForce claimed the city as a victim; the city has not verified responsibility or the group’s asserted data volume.

Jurisdiction of affected city government; only documented service effects are asserted.
DysruptionHub reported the city network incident, Friday office closure and the city’s assurance that police, fire and water services continued.
The city reported a network incident disrupting computer systems, took affected systems offline and said essential public safety and water services remained operational.
The city called the event a network compromise, said unusual activity was detected Friday morning, and described closed offices, staff sent home and manual work processes.
City Hall and City Court were to reopen with limited functions Oct. 30; the library remained closed and city meetings could not be livestreamed.
The library reopened with limited hours and services amid ongoing outages; books could not be checked out and public computers were unavailable.
The Vermont attorney general listing dated June 23, 2026 names the City of La Vergne and lists one Vermont resident and Social Security numbers.
The city confirmed that notification letters were sent to individuals potentially affected by its October 2025 cybersecurity incident.
Massachusetts breach number 2026-1039 lists the City of La Vergne, 14 Massachusetts residents affected and Social Security numbers breached.
Comparitech reported a DragonForce claim of 382 gigabytes stolen and an extortion deadline, while noting that city officials had not verified the claim.
The tracker records a DragonForce listing naming the City of La Vergne and its official website; the listing does not verify the group’s responsibility.
Signed-in members can report an error, update, or missing source.