Skip to content

Palouse restores city website after cyberattack

Summary

City of Palouse logo

The City of Palouse, Washington restored its public website from a hosting-provider backup after officials said the site had been hacked. Some recently added content was missing and required re-entry, while the city reported that no sensitive data was involved.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub’s reporting documented that Palouse, Washington restored its public city website after a cyberattack. The May 1 report said the city recovered the site using a backup from its hosting provider, while some recently added content had been lost and needed to be re-entered.

DysruptionHub assesses with high confidence that a malicious website compromise occurred. The City of Palouse’s April 14 council minutes state directly that the city website had recently been hacked, that no sensitive data was involved, and that the hosting company restored the site from backup. The minutes establish that the compromise and restoration occurred before or by April 14, but they do not provide either exact date.

Operational significance

The incident affected a public-facing municipal website used to provide city information, contact details, alerts, records, and links to online services. Restoration from backup returned the site to service, but some recently added content was missing and required manual re-entry. That created a limited public-information and records-maintenance impact rather than a documented interruption to core municipal operations.

The reviewed evidence does not show that emergency services, public safety, utilities, internal city networks, payment systems, email, or administrative applications were affected. The operational scope is therefore limited to the website and associated content-management work.

Disclosure posture

The clearest primary disclosure appears in official city council minutes dated April 14. The city confirmed the hack, the backup-based restoration, the loss of some recent content, and its conclusion that sensitive data was not involved.

The city did not disclose when the intrusion began, how long the website was unavailable, how access was obtained, whether malicious content was placed on the site, or whether law enforcement or a forensic provider was involved. No threat actor, ransom demand, or ransomware activity was identified in the reviewed record.

Confidence and uncertainty

Confidence is high that the website was compromised and restored because the city recorded both facts in official minutes. Confidence is also high that some recent website content became unavailable after restoration.

The evidence does not establish whether the missing content was deleted by the attacker, omitted because the backup predated recent updates, or lost through another restoration effect. The city’s statement supports high confidence that sensitive data was not involved, reducing the confidentiality concern. It does not negate the confirmed availability loss represented by missing recent content.

Current status

The city had already restored the website by the April 14 council meeting. Because the official record provides positive restoration evidence, DysruptionHub assesses the incident as resolved. The exact restoration date remains unknown.

Analytic gaps

The reviewed sources do not establish the initial compromise date, restoration date, outage duration, access vector, exploited vulnerability, affected account, malicious tooling, persistence, hosting environment, or whether any pages were altered before restoration. They also do not identify the exact content lost, the amount of staff time required for re-entry, or whether any third-party service beyond the hosting provider was affected.

Organizations involved

Impacted location

Sources

Palouse, Washington, restores city website after cyberattack

DysruptionHub reported that Palouse restored its city website after a cyberattack using a hosting-provider backup. Some recently added content was lost and required re-entry, while officials said no sensitive data was compromised.

City Council Minutes — April 14, 2026

The city administrator reported that the city website had recently been hacked, no sensitive data was involved, the hosting company restored it from backup, and some recently added content might be missing and require re-entry.

See something that needs correction?

Signed-in members can report an error, update, or missing source.