City of Palouse

The City of Palouse, Washington restored its public website from a hosting-provider backup after officials said the site had been hacked. Some recently added content was missing and required re-entry, while the city reported that no sensitive data was involved.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A public-facing website was unavailable, disabled, or inaccessible.
The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
Our reporting documented that Palouse, Washington, restored its public city website after a cyberattack. The May 1 report said the city recovered the site using a backup from its hosting provider, while some recently added content had been lost and needed to be re-entered.
DysruptionHub assesses with high confidence that a malicious website compromise occurred. The City of Palouse’s April 14 council minutes state directly that the city website had recently been hacked, that no sensitive data was involved, and that the hosting company restored the site from backup. The minutes establish that the compromise and restoration occurred before or by April 14, but they do not provide either exact date.
The incident affected a public-facing municipal website used to provide city information, contact details, alerts, records, and links to online services. Restoration from backup returned the site to service, but some recently added content was missing and required manual re-entry. That created a limited public-information and records-maintenance impact rather than a documented interruption to core municipal operations.
The reviewed evidence does not show that emergency services, public safety, utilities, internal city networks, payment systems, email, or administrative applications were affected. The operational scope is therefore limited to the website and associated content-management work.
The clearest primary disclosure appears in official city council minutes dated April 14. The city confirmed the hack, the backup-based restoration, the loss of some recent content, and its conclusion that sensitive data was not involved.
The city did not disclose when the intrusion began, how long the website was unavailable, how access was obtained, whether malicious content was placed on the site, or whether law enforcement or a forensic provider was involved. No threat actor, ransom demand, or ransomware activity was identified in the reviewed record.
Confidence is high that the website was compromised and restored because the city recorded both facts in official minutes. Confidence is also high that some recent website content became unavailable after restoration.
The evidence does not establish whether the missing content was deleted by the attacker, omitted because the backup predated recent updates, or lost through another restoration effect. The city’s statement supports high confidence that sensitive data was not involved, reducing the confidentiality concern. It does not negate the confirmed availability loss represented by missing recent content.
The city had already restored the website by the April 14 council meeting. Because the official record provides positive restoration evidence, DysruptionHub assesses the incident as resolved. The exact restoration date remains unknown.
The reviewed sources do not establish the initial compromise date, restoration date, outage duration, access vector, exploited vulnerability, affected account, malicious tooling, persistence, hosting environment, or whether any pages were altered before restoration. They also do not identify the exact content lost, the amount of staff time required for re-entry, or whether any third-party service beyond the hosting provider was affected.

DysruptionHub reported that Palouse restored its city website after a cyberattack using a hosting-provider backup. Some recently added content was lost and required re-entry, while officials said no sensitive data was compromised.
The city administrator reported that the city website had recently been hacked, no sensitive data was involved, the hosting company restored it from backup, and some recently added content might be missing and require re-entry.
Signed-in members can report an error, update, or missing source.