Skip to content

City of La Vergne Network Compromise

Summary

City of La Vergne logo

The City of La Vergne disclosed a network compromise in October 2025 that closed public offices, took systems offline and limited library services for weeks. The city later sent breach notifications, while a DragonForce extortion claim remains unverified.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data exposure

    Data was made accessible to unauthorized parties through misconfiguration, system compromise, improper access controls, or another unintended condition.

Operational impacts

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Facility closure

    One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that the City of La Vergne experienced a cyber incident that disrupted municipal computer systems in October 2025. The city reported on Oct. 17 that it had taken affected systems offline, engaged cybersecurity specialists and law enforcement, and kept public safety and water services operating. Its Oct. 20 update described a compromise of the city network and said unusual activity had been detected on the morning of Oct. 17. That is the first established detection date, not proof of when unauthorized activity began.

The DragonForce listing names the city as a claimed victim. Comparitech reported that the group alleged it had stolen 382 gigabytes of data and threatened release. The city has not publicly verified the group’s responsibility, the claimed quantity or the use of ransomware. The listing supports an extortion claim, not confirmed encryption or attribution.

Operational significance

The city said its offices closed to the public and employees were sent home early while the network was offline. Managers used manual processes to keep work going, according to the Oct. 20 city update. By Oct. 29, City Hall and City Court were preparing to resume regular hours with limited functions, the public library remained closed, and city meetings could not be livestreamed.

The library reopened with limited services on Nov. 13, but books could not be checked out and public computers were unavailable. This shows that disruption to a resident-facing service lasted at least into mid-November. The city’s initial statement said essential public safety and water services remained operational; the reviewed sources do not establish interruption of emergency response or water delivery.

Disclosure posture

The city’s early public notices described the network disruption and service limitations. In June 2026, the city confirmed that it had sent legitimate notification letters to people who might have been affected by the October incident. A Massachusetts breach report lists 14 residents affected and Social Security numbers breached; a Vermont attorney general listing also identifies Social Security numbers for one resident. Those records substantiate a personal-information impact for notified people, but do not establish how the information was obtained, whether it was exfiltrated, or whether DragonForce possessed it.

Retrospective note

The last reviewed city notice showing an operational limitation was the Nov. 13 library update. Because that notice is nearly a year old and no final restoration statement was found, DysruptionHub assesses that the operational disruption is presumed resolved while the precise recovery date remains unknown. The 2026 notification process is a later consequence of the incident, not evidence that city systems remained disrupted then.

Confidence and uncertainty

Confidence is high that a cyber-related network compromise occurred and affected city services because the city directly documented both. Confidence is high that notification involved Social Security numbers for at least some recipients because state breach records identify that data category. Confidence is low in DragonForce attribution and its claimed data volume: the group made the allegation, but independent public verification was not found. Ransomware encryption remains unestablished.

Analytic gaps

The reviewed record does not establish initial access, the specific attack mechanism, malware, the full set of affected systems, when unauthorized activity began, the total number of people affected, the scope of any data transfer, the ransom demand or payment status, or the date all municipal and library functions were restored.

Threat actor and claim

Listed as: City of La VergneSource: ransomware.live

Claim details

DragonForce claimed the city as a victim; the city has not verified responsibility or the group’s asserted data volume.

Organizations involved

Impacted location

Sources

La Vergne, Tennessee, says network incident hit city systems

DysruptionHub reported the city network incident, Friday office closure and the city’s assurance that police, fire and water services continued.

City Investigating Cybersecurity Incident

The city reported a network incident disrupting computer systems, took affected systems offline and said essential public safety and water services remained operational.

City Offices Remain Closed to Public

The city called the event a network compromise, said unusual activity was detected Friday morning, and described closed offices, staff sent home and manual work processes.

City Services Update, Oct. 29

City Hall and City Court were to reopen with limited functions Oct. 30; the library remained closed and city meetings could not be livestreamed.

Library Reopens with Limited Services

The library reopened with limited hours and services amid ongoing outages; books could not be checked out and public computers were unavailable.

Security Breach Notices

The Vermont attorney general listing dated June 23, 2026 names the City of La Vergne and lists one Vermont resident and Social Security numbers.

Cybersecurity Notification Letters

The city confirmed that notification letters were sent to individuals potentially affected by its October 2025 cybersecurity incident.

2026 Data Breach Notification Report

Massachusetts breach number 2026-1039 lists the City of La Vergne, 14 Massachusetts residents affected and Social Security numbers breached.

DragonForce claim for City of La Vergne

The tracker records a DragonForce listing naming the City of La Vergne and its official website; the listing does not verify the group’s responsibility.

See something that needs correction?

Signed-in members can report an error, update, or missing source.