City of University City

University City, Missouri, confirmed that malicious cyber activity caused a network outage first publicized June 17, 2026, disrupting permitting, public-record access, card processing and online bill payment. Some services had returned by July 23, but the city still prominently featured its outage alert on August 3 and had not announced full restoration.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Internal or external network connectivity was unavailable or materially impaired.
The organization could not process, receive, issue, reconcile, or record payments normally.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
DysruptionHub assesses with high confidence that malicious cyber activity caused University City, Missouri’s prolonged municipal network outage. In a July 23 response reported by DysruptionHub, city communications manager Jared Jones said an attack carried out with malicious intent disrupted network connections and blocked access to essential systems and online services.
The city first publicly reported a network outage on June 17, describing the cause as server issues. Jones later said the city became aware of the network disruption June 19, two days after that notice. The public record does not resolve the date discrepancy or establish when malicious activity began.
The outage disrupted online bill payment, credit and debit card processing, permitting and access to certain public records. KSDK reported that in-person card payments for parking tickets and other applicable city services were also affected and that staff used temporary manual processes and alternatives. City phone lines remained operational, and the public record does not establish disruption to police, fire, emergency communications or utility operations.
University City initially described the event as a network outage related to server issues and declined in June to discuss its specific cause while review was underway. The July 23 confirmation materially changed the public characterization from an unexplained outage to organization-confirmed malicious cyber activity. The evidence does not establish that the earlier wording was intentionally misleading.
The incident remains active. On August 3, the city’s official homepage still prominently featured the network-outage alert and linked to the June 17 notice. Permitting, online bill-pay and public-document links were present, which are credible recovery signals, but the city had not posted a full-restoration statement or withdrawn the alert.
The latest detailed city account remained the July 23 statement that some systems and online services had been restored while rebuilding and restoration continued in phases without a confirmed completion date. The continuing official alert supports treating August 3 as the latest observed date of operational impact, not as a known restoration date.
Confidence is high that malicious activity caused the outage because University City confirmed it directly. The city said it stopped the malicious activity before personal information could be taken and had found no evidence that personal information was accessed or removed; because the investigation remained open, that statement is a current negative finding rather than a final determination covering every possible data effect.
The public record does not support confirmed ransomware, extortion or threat-actor attribution. It also does not identify a specific attack mechanism, so DysruptionHub assesses the mechanism as unknown.
The public record does not establish the initial-access vector, exploited vulnerability, malware family, affected hosts or applications, attacker identity, dwell time, vendor involvement, backup impact, law-enforcement notification, ransom demand or payment, or the reason for the June 17 and June 19 chronology conflict. It also does not identify which services remained unavailable after July 23 or provide a final restoration date.

The city homepage continued to feature the network-outage alert prominently on August 3 and linked to the June 17 notice. Permitting, online bill-pay and public-document links were present, but no full-restoration statement was posted.
University City communications manager Jared Jones told DysruptionHub that malicious activity caused the outage, disrupted network connections and blocked essential systems and online services. The city said some services were restored in phases, recovery remained ongoing with no full-restoration date, and it had found no evidence that personal information was accessed or removed.
The city said it was experiencing a network outage due to server issues. Phone lines remained operational, but permitting services, public-document requests, card payment processing and online bill pay were unavailable.
The city said the June 22 network outage related to ongoing server issues continued, affected services had not been restored, staff and technical-support personnel were making progress toward a solution, and no estimated full-restoration time was available.
KSDK reported that University City identified the disruption as a malicious cyberattack, that some services still required restoration, and that staff used temporary manual processes and alternatives. The city said it had no evidence residents’ personal information was accessed or removed.
Signed-in members can report an error, update, or missing source.