Skip to content

City of Michigan City Ransomware Attack

Summary

City of Michigan City logo

A Sept. 23, 2025, ransomware incident disrupted Michigan City employees’ online and telephone access. The city took parts of its network offline while police, central services and emergency dispatch continued. It later disclosed that its investigation found certain data had been accessed or acquired. Obscura claimed responsibility and a 450 GB theft, which the city has not verified.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

Operational impacts

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

The City of Michigan City reported a network disruption on Sept. 25 and confirmed on Oct. 10 that the Sept. 23 event was ransomware. City employees lost some online and telephone access. The city took network segments offline, called in outside specialists and law enforcement, and worked to restore systems. DysruptionHub reported the confirmation on Oct. 10.

Operational significance

The city’s initial statement said the police department and central services were operating and emergency dispatch was unaffected. The incident still impeded municipal staff communications and access to online systems. An Oct. 21 council agenda said minutes from the Sept. 16 and Oct. 7 meetings were delayed because of the city computer disruption. This supports a records-processing effect; it does not imply police, dispatch or citywide services stopped.

Data and extortion claims

In a preliminary notice published Nov. 5, the city said its investigation had determined on Sept. 28 that certain data had been accessed or acquired. The city was reviewing what information might have been affected and said it had no evidence of misuse. That notice supports unauthorized data access or acquisition, but did not quantify the data, name affected people or tie its finding to a named group.

An Obscura listing named the city’s domain and claimed a 450 GB theft and publication. The Record reported the group’s allegation. Those are extortion claims, not independent verification that Obscura caused the intrusion or that its alleged data volume is authentic.

Status and gaps

The reviewed public record does not give a date when all affected city systems returned to normal. It also does not establish the initial access vector, encryption scope, total number of people affected, exact data categories, ransom demand or payment. The city has not publicly corroborated the Obscura attribution or the alleged 450 GB figure in the reviewed material.

Threat actor and claim

Listed as: michigancityin.govSource: ransomware.live

Claim details

Obscura claimed Michigan City and a 450 GB data leak; the city has not confirmed this actor, volume or alleged publication.

Organizations involved

Impacted location

  • Michigan City, Indiana

    City's physical place anchor; no separate building damage asserted.

    Geographic remit of the affected city government; does not imply every city service or resident was affected.

Sources

City of Michigan City Network Disruption Update

The city said the Sept. 23 network disruption prompted it to take parts of the network offline; police, central services and emergency dispatch were operating.

Update on Michigan City Network Disruption

The city confirmed that its Sept. 23 network disruption was ransomware and affected municipal employee online and telephone access.

Indiana city confirms ransomware hackers behind September incident

The Record reported the city’s ransomware confirmation and Obscura’s separate allegation of a 450 GB theft and data publication.

October 21, 2025 Common Council agenda

The council agenda said two sets of meeting minutes were delayed because of the network disruption with city computers.

Preliminary Notice of Data Event

The city said its investigation determined that certain data had been accessed or acquired; review of affected information was ongoing and there was no evidence of misuse.

Obscura claim for michigancityin.gov

The tracker records Obscura naming michigancityin.gov and claiming a 450 GB leak.

See something that needs correction?

Signed-in members can report an error, update, or missing source.