City of University City

University City, Missouri, confirmed that malicious cyber activity caused a network outage first publicized June 17, 2026, disrupting permitting, public-record access, card processing and online bill payment. On August 6, the city said affected systems and services had been restored and that its investigation found no evidence personal information was accessed, removed or compromised.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Internal or external network connectivity was unavailable or materially impaired.
The organization could not process, receive, issue, reconcile, or record payments normally.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
DysruptionHub assesses with high confidence that malicious cyber activity caused University City, Missouri’s prolonged municipal network outage. In a July 23 response reported by DysruptionHub, city communications manager Jared Jones said an attack carried out with malicious intent disrupted network connections and blocked access to essential systems and online services.
The city first publicly reported a network outage on June 17, describing the cause as server issues. Jones later said the city became aware of the network disruption June 19, two days after that notice. The public record does not resolve the date discrepancy or establish when malicious activity began.
The outage disrupted online bill payment, credit and debit card processing, permitting and access to certain public records. KSDK reported that in-person card payments for parking tickets and other applicable city services were also affected and that staff used temporary manual processes and alternatives. City phone lines remained operational, and the public record does not establish disruption to police, fire, emergency communications or utility operations.
University City initially described the event as a network outage related to server issues and declined in June to discuss its specific cause while review was underway. The July 23 confirmation materially changed the public characterization from an unexplained outage to organization-confirmed malicious cyber activity. The evidence does not establish that the earlier wording was intentionally misleading.
The incident is resolved. In an August 6 update, University City said the systems and services affected by the cyberattack had been successfully restored. The notice provides the first authoritative full-restoration statement and supports August 6 as the incident’s end date.
August 3 remains the latest date of directly observed operational impact because the city’s outage alert was still prominently displayed then. The August 6 notice establishes recovery but does not say that disruption continued through the date of publication.
Confidence is high that malicious activity caused the outage and that affected services were restored because University City confirmed both findings directly. Service and public-record unavailability establish an availability impact. The city said its investigation found no evidence that personal information was accessed, removed or compromised, providing a high-confidence negative finding on known confidentiality compromise without negating the documented availability impact.
The public record does not support confirmed ransomware, extortion or threat-actor attribution. It also does not identify a specific attack mechanism, so DysruptionHub assesses the mechanism as unknown.
The public record does not establish the initial-access vector, exploited vulnerability, malware family, affected hosts or applications, attacker identity, dwell time, vendor involvement, backup impact, law-enforcement notification, ransom demand or payment, or the reason for the June 17 and June 19 chronology conflict. The city has not published a more detailed forensic report.

University City communications manager Jared Jones told DysruptionHub that malicious activity caused the outage, disrupted network connections and blocked essential systems and online services. The city said some services were restored in phases, recovery remained ongoing with no full-restoration date, and it had found no evidence that personal information was accessed or removed.
The city said it was experiencing a network outage due to server issues. Phone lines remained operational, but permitting services, public-document requests, card payment processing and online bill pay were unavailable.
The city said the June 22 network outage related to ongoing server issues continued, affected services had not been restored, staff and technical-support personnel were making progress toward a solution, and no estimated full-restoration time was available.
KSDK reported that University City identified the disruption as a malicious cyberattack, that some services still required restoration, and that staff used temporary manual processes and alternatives. The city said it had no evidence residents’ personal information was accessed or removed.
University City said August 6 that systems and services affected by the cyberattack had been successfully restored. The city also said a thorough investigation found no evidence that personal information was accessed, removed or compromised.
The city homepage continued to feature the network-outage alert prominently on August 3 and linked to the June 17 notice. Permitting, online bill-pay and public-document links were present, but no full-restoration statement was posted.
Signed-in members can report an error, update, or missing source.