City of Martinsville, Virginia

The City of Martinsville, Virginia, detected a cyberattack March 25, 2026, that disrupted computer systems and delayed or limited services in the municipal building. City Manager Robert Fincher said April 9 that city services were fully operational. A later city notice said personal information might have been accessed but reported no evidence of misuse.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Services remained available but with reduced performance, reliability, functionality, capacity, or responsiveness.
Services continued but with longer processing, response, delivery, or completion times.
The City of Martinsville experienced a confirmed cyber incident that disrupted municipal computer systems. The city called the event a cyberattack March 25, 2026, said it contained the activity and warned that some services in the City Municipal Building could be delayed or limited for the rest of the week. An April 9 WFXR report quoted City Manager Robert Fincher saying city services were fully operational.
A later city notice said the technology team acted immediately after detecting computer-system disruptions and engaged outside cybersecurity experts. The city said its systems were secure and operations had returned to normal.
The documented effect was delayed or restricted service in the municipal building. The April 9 report said Martinsville waived utility-payment late fees associated with the disruption. Public sources do not identify every affected department or establish interruption of emergency services, utilities or public safety operations.
Martinsville publicly identified the event as a cyberattack and acknowledged possible service delays March 25. That organization-first cyber and disruption disclosure supports an OC-OD classification.
The initial statement said no consumer or citizen information had been compromised. The later notice said names, addresses, dates of birth, driver’s license numbers, Social Security numbers, financial information and employee benefit or medical information might have been accessed. The city reported no evidence of misuse and offered identity monitoring as a precaution.
The incident is resolved. April 9 is the first dated positive evidence that all city services were operational. March 27 remains the last dated observation of operational impact because the recovery statement does not establish that disruption continued through April 9.
Confidence is high that malicious cyber activity disrupted city systems and that services recovered. Ransomware, threat-actor attribution and actual data access remain unresolved. Searches using the city’s canonical name and martinsville-va.gov did not identify a stable leak-site or extortion claim.
Public sources do not establish the initial access vector, malware family, persistence method, encryption, confirmed exfiltration, affected-record count, ransom demand, threat actor or department-level impact.

Martinsville said a cyberattack had been contained but warned that municipal-building services could be delayed or limited for the rest of the week; the city did not identify affected services or an actor.
WFXR reported the city’s social media statement saying a cyberattack was contained and that some municipal-building services might be temporarily delayed or limited for the remainder of the week.
City Manager Robert Fincher said April 9 that city services were fully operational after the March 25 cyberattack. The report also said Martinsville waived utility-payment late fees associated with the disruption.
The city said it detected computer-system disruptions around March 25, stopped the incident with outside experts, secured its systems and returned operations to normal; it said personal information might have been accessed but reported no evidence of misuse.
The organization’s official website describes its identity, services, operating role and public or customer-facing programs.
The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.
Signed-in members can report an error, update, or missing source.