City of Leavenworth

A cyberattack disrupted Leavenworth, Kansas, municipal systems beginning Nov. 19, 2025. The city confirmed the cyber cause Nov. 25 and directed vendors, permit applicants and job seekers to use mail or in-person workarounds while it restored services.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Internal or external network connectivity was unavailable or materially impaired.
Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
DysruptionHub assesses with high confidence that the City of Leavenworth, Kansas, experienced a cyberattack that disrupted its internal network in November 2025. The city’s Nov. 25 update says its investigation determined that the network problems stemmed from a cyberattack. The city had first reported a network interruption Nov. 19.
The city said invoice processing, online permits and inspections, and emailed employment applications could require workarounds. It directed people to mail or deliver applications and permit requests to City Hall. Our reporting also documented limited phone and email access during the initial outage. The city said emergency operations were unaffected.
On Dec. 4, the city manager described the network as mostly functional, according to the Leavenworth Times account cited in our report. The public record reviewed here does not establish a full restoration date or a final technical all-clear. The incident is therefore presumed resolved as of this retrospective review; that classification does not assert that every system was restored by Dec. 4.
The city initially described a network outage and later identified a cyberattack on Nov. 25. Its statement said it was not then aware of compromised sensitive information but that the question remained under investigation.
The city’s direct statement supports high confidence in cyber involvement and documented service disruption. No reviewed source identifies the attack mechanism, ransomware, a ransom demand, a threat actor or confirmed data access.
The initial access vector, affected systems, complete outage duration, final restoration, forensic findings and data-exposure outcome remain unresolved.

City Hall place anchor; the city's internal network was affected.
We reported that the November cyberattack disrupted Leavenworth municipal services, limited phone and email access, and left some payment, permitting and hiring functions on manual workarounds in early December.
The city said its investigation determined the network problems stemmed from a cyberattack and warned that vendor invoices, online permits and inspections, and emailed job applications could require mail or in-person workarounds.
Signed-in members can report an error, update, or missing source.