Claim details
Qilin claimed the city; a secondary outlet reported its 800 GB theft allegation. Neither responsibility nor data volume is confirmed by the city.
An Oct. 9, 2025, cyber incident forced Sugar Land, Texas, to take its network offline. The city documented disruption to dispatch tools, water monitoring, phones and business systems; 911 remained available, and staff used manual workarounds. Most internet access returned within five days. Qilin later claimed a breach and data theft, which the city has not publicly verified.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
The City of Sugar Land reported a cyber-event on Oct. 9, 2025, and said police were investigating a breach of its internal network with local, state and federal partners. DysruptionHub reported the resulting service outages on Oct. 10. The city’s 2025 police annual report later confirmed the city took its network offline as part of the response.
The police report says public safety dispatch systems, water monitoring, business operations and phone lines were disrupted. Emergency 911 and some cloud tools remained functional; the city activated its Emergency Operations Center and used manual workarounds. The city’s contemporaneous service notice, as reported by The Record, listed 311, utility billing, permit and inspection scheduling, permit payments and building applications as unavailable. A later city update said critical infrastructure remained operational and 911 could still be reached. The Houston Chronicle reported that the city suspended utility disconnections and late fees while payment service was unavailable. The annual report says most internet access returned within five days; it does not provide a date when every system was fully restored.
A Qilin listing appeared on Oct. 25. TechNadu reported the group’s allegation that it stole 800 GB and threatened publication. The reviewed city materials do not confirm Qilin’s involvement, data theft, the alleged volume or ransomware deployment. Those details remain actor claims. The initial access method and final data impact are also unresolved in the reviewed public record.
Qilin claimed the city; a secondary outlet reported its 800 GB theft allegation. Neither responsibility nor data volume is confirmed by the city.

Government service area; does not imply every resident or facility lost service.
City place anchor for affected government operations; no individual facility damage asserted.
DysruptionHub reported the city network breach, online service disruption and continued 911 service.
The city reported a cyber-event and investigation of a breach of internal network infrastructure; a public-records suspension ran Oct. 9-15 and was extended Oct. 16-22.
City update said critical infrastructure remained operational, bill pay was affected, and 911 was available.
City post listed 311, utility billing, permit and inspection scheduling, permit payments and building applications as unavailable.
The Record reported the city notices and named affected services, including 311, utility payments and permit functions.
A city spokesperson said phone, internet and payment restoration continued; the city paused utility disconnections and late fees.
Ransomware.live recorded Qilin listing the City of Sugar Land on Oct. 25.
TechNadu reported Qilin claimed an 800 GB theft and threat to release data; city had not verified the claim.
Page 27 says the Oct. 9 cyber incident forced the city network offline, disrupting public safety dispatch, water monitoring, business operations and phones; 911 worked, manual workarounds were used, and most internet access returned within five days.
Signed-in members can report an error, update, or missing source.