Skip to content

City of York ransomware incident

Summary

City of York logo

A ransomware incident that began on July 8, 2025 disrupted City of York email, computers and parking-garage kiosks for weeks. The city’s insurer reportedly negotiated a $1 million demand to $500,000 and paid it, and York later confirmed that an unknown actor accessed its network and accessed or acquired files.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

External sources identified the event as cyber-related before the organization publicly confirmed it. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Payment processing disruption

    The organization could not process, receive, issue, reconcile, or record payments normally.

  • Transaction processing disruption

    Business, financial, customer, administrative, or operational transactions could not be completed normally.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Encryption-based extortion

    The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.

  • Payment reported

    A source reported that the victim, insurer, intermediary, or another party made a ransom or extortion payment.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that the City of York, Pennsylvania, experienced a ransomware incident beginning July 8, 2025. A York Daily Record investigation reported that then-Mayor Michael Helfrich said attackers seized control of the city’s IT infrastructure, disabled email and parking kiosks, and demanded $1 million. The city’s insurer reportedly negotiated the demand to $500,000 and paid it, while York paid a $25,000 deductible.

The city’s Notice of Data Event independently confirms malicious access. York said an unknown actor accessed portions of its network July 8, 2025, and accessed or acquired certain files. That notice establishes unauthorized activity and a data impact, although it does not identify the ransomware family, initial access vector or responsible actor.

Operational significance

The incident materially disrupted municipal operations. Our April 17 report documented that city email was unavailable for about two weeks, digital kiosks at York’s three parking garages were disabled for about three weeks, and staff collected parking payments manually at posted flat rates. Helfrich also said employees lacked normal access to computers and email, while the incident delayed work on city audits that were already years behind.

Parking service was restored Aug. 11, according to the later reporting. Helfrich said the broader matter was not fully resolved until around September. Those statements support a resolved operational status, but the public record does not provide a precise final restoration date or a technical all-clear covering every affected system.

Disclosure posture

The city did not publicly characterize the incident as ransomware while the disruption was underway. An August 2025 report documented the parking interruption and manual payment process, but Helfrich declined to say whether a security breach caused it. Our reporting later found that internal city communications urged control over how details were shared and that a planned July 15 news conference was postponed during ransomware negotiations.

York’s official record evolved over time. The city’s February 17, 2026, council minutes recorded references to a cyberattack on city infrastructure and public calls for transparency. The June data-event notice then confirmed unauthorized network access and file acquisition but did not address the ransom demand or payment.

Retrospective note

York’s data notice confirms that files were accessed or acquired. It lists potentially involved information categories including names, Social Security numbers, dates of birth, driver’s-license numbers, financial account information, taxpayer identification numbers, medical information and health-insurance information. The notice does not state how many people were affected, which categories applied to any particular person or whether the acquired files were used or publicly released.

Confidence and uncertainty

Confidence is high that malicious cyber activity caused the disruption because York confirmed unauthorized network access and inaccessible systems, and the former mayor described the event as ransomware. Confidence is also high that a ransom demand and insurance-backed payment occurred, based on the York Daily Record’s account of the former mayor’s statements and records obtained through a public-records request.

Threat-actor attribution remains unresolved. An internal update reportedly described the attackers as a known Russian group, but York has not publicly named an actor and no public extortion-site claim has been identified. Data access or acquisition is confirmed by the city, while the full exfiltration scope, affected population and any subsequent disclosure or misuse remain unestablished.

Analytic gaps

The public record does not establish the initial access vector, exploited vulnerability, compromised account or host, dwell time, ransomware family, encryption scope, lateral movement, persistence method, recovery architecture or whether the payment produced a functional decryptor. It also does not identify the responsible actor, explain whether law enforcement attributed the incident, or provide a final incident report.

York has not published the number of affected people, the exact files acquired, the data categories applicable to each person, or evidence of public release or misuse. The exact date on which every city system returned to normal also remains unclear.

Organizations involved

Impacted location

Sources

City of York, Pennsylvania, never disclosed 2025 ransomware payout

DysruptionHub reported that the July 2025 incident disabled York city email for about two weeks and parking-garage kiosks for about three weeks. It said the insurer negotiated a $1 million demand to $500,000 and paid it, while the city paid a $25,000 deductible, and that the parking system was restored August 11.

IT reviewing York City's recent parking garage issues, mayor says

The August 2025 report documented a parking-garage system interruption lasting at least three weeks. Staff collected payments manually and the city posted flat parking rates, while then-Mayor Michael Helfrich declined to say whether the outage was connected to a security breach.

York City cyberattack led to $500K ransom payout, former mayor says

The York Daily Record investigation reported that former Mayor Michael Helfrich said the attack began July 8, 2025, locked the city out of computers and email, disabled garage kiosks, and prompted a $1 million demand that the insurer negotiated to $500,000. The report said email was down about two weeks and parking systems about three weeks.

York City Council Minutes - February 17, 2026

The minutes recorded that York’s audit-reconciliation work had been further complicated by a cyberattack on city infrastructure. They also recorded a council member’s remarks about a ransomware attack reported in the media and a request for continued transparency about the city’s digital infrastructure.

Notice of Data Event

The City of York said it became aware that computer network systems were inaccessible. Its investigation determined that an unknown actor accessed portions of the network on July 8, 2025 and accessed or acquired certain files; potentially involved information includes identity, financial, medical and health-insurance data.

History

York’s official history describes the town’s 1741 layout along Codorus Creek and the Continental Congress’s residence in York during 1777 and 1778.

Geographic profiles for selected U.S. locations

Official geographic reference used with local and state material to verify place names, jurisdiction types and location context for york, york.

See something that needs correction?

Signed-in members can report an error, update, or missing source.