Skip to content

DeKalb County sheriff ransomware incident

Summary

DeKalb County Sheriff's Department logo

Ransomware disrupted the DeKalb County Sheriff’s Department and jail server March 13, interrupting email and inmate booking. Booking data was recovered that evening, but the public record does not provide a full restoration date, identify the ransomware family or establish data theft.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Data encryption

    Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Public safety operations disrupted

    Police, fire, emergency medical, corrections, emergency management, or other public-safety operations were materially affected.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

We reported that ransomware disrupted the DeKalb County Sheriff’s Department and jail main server March 13, 2026, interrupting email and inmate-booking software. Sheriff Patrick Ray’s direct ransomware description provides concrete cyber evidence and supports confirmed ransomware, although no ransomware family or responsible actor has been identified.

Operational significance

Correctional officers first noticed the problem during an inmate intake when the booking program stopped working, according to WJLE Radio. The affected server also controlled department email. Jail staff recovered the booking data that evening, limiting the documented duration of that specific function’s outage, while broader investigation and recovery continued March 14.

The documented effects were confined to the sheriff’s department and jail in Smithville, Tennessee. The public record does not establish disruption to 911, patrol dispatch or another county agency.

Disclosure posture

The sheriff publicly identified the event as an external ransomware intrusion March 14. No earlier external claim or public cyber characterization was identified, supporting organization-confirmed cyber and organization-documented disruption.

Current status

The immediate booking data was recovered March 13, and no later outage report was found. The record does not provide a full technical or operational all-clear, however, so the incident is presumed resolved rather than resolved on a documented date.

Confidence and uncertainty

Confidence is high that ransomware disrupted email and booking because the sheriff directly identified ransomware and described those effects. The account supports file encryption and temporary data unavailability, but it does not establish data theft or exposure.

No stable ransomware or extortion victim claim was identified by the department’s name, a supported office alias or dekalbtennessee.com. No ransom demand, payment deadline, negotiation or payment has been publicly disclosed.

Analytic gaps

The public record does not establish the ransomware family, initial access vector, encryption scope, attacker dwell time, persistence, lateral movement, ransom demand, payment, data exfiltration, number of affected systems or full restoration date.

Organizations involved

Impacted locations

Sources

DeKalb County sheriff and jail hit by ransomware

A ransomware attack disrupted department email and inmate booking at the sheriff’s office and jail in Smithville.

Sheriff’s Department and Jail’s main computer server hacked

Sheriff Patrick Ray said correctional officers first noticed the booking-program failure early March 13 during an inmate intake. He described an external ransomware intrusion affecting the main server, department email and booking software. Booking data was recovered that evening, while investigation and broader recovery continued March 14.

DeKalb County Sheriff's Department official website

The organization’s official website describes its identity, services, operating role and public or customer-facing programs.

Gazetteer Files

The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.

See something that needs correction?

Signed-in members can report an error, update, or missing source.