Delaware County cyberattack disrupts county systems
Summary
Delaware County, Pennsylvania, identified unauthorized intrusion attempts on June 26, 2026, and shut down network systems to protect sensitive information. Attackers gained limited access to the county network and data, while phones, servers, financial software, libraries and other public services were disrupted; some network issues remained publicly flagged on July 26.
Key facts
Timeline
-
First public signal:
?
Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity. -
First public cyber evidence:
?
Earliest credible public information connecting the incident or disruption to malicious cyber activity. -
Official cyber disclosure:
?
First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related. -
Last impact seen:
?
Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
Primary victim organization
DysruptionHub coverage
Impacted locations
Organization types
Critical infrastructure sector
Incident characteristics
Assessments
- Status:
- Active
- Incident confidence:
- High
- Ransomware:
- Unresolved
DD-CIT classification
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Attack mechanisms
-
Unauthorized access
Unauthorized access to systems, accounts, networks, or data.
Data impacts
-
Unauthorized data access
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
-
Data unavailable
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Operational impacts
-
Partial service outage
A service, system, platform, or operational capability remained available only in part or with significant limitations.
-
Network outage
Internal or external network connectivity was unavailable or materially impaired.
-
Phone service disruption
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
-
Online portal unavailable
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
-
Internal systems unavailable
Internal business, administrative, operational, or staff-facing systems were unavailable.
-
Application unavailable
A specific application or software platform became unavailable or unusable.
-
Records access disruption
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
-
Public safety operations disrupted
Police, fire, emergency medical, corrections, emergency management, or other public-safety operations were materially affected.
-
Government services disrupted
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
-
Service delay
Services continued but with longer processing, response, delivery, or completion times.
-
Manual workaround required
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
-
Alternate service channel required
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
-
Staff unable to work normally
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
-
Customer or public access restricted
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Extortion indicators
-
No known extortion indicator
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
Incident narrative
Analyst assessment
DysruptionHub assesses with high confidence that Delaware County, Pennsylvania, experienced a malicious network intrusion that caused material government-service disruption. The county’s July 2 statement said it identified unauthorized activity on June 26 and shut down network access to protect sensitive information and critical systems. A July 10 update characterized the activity as a sophisticated cybercriminal attack and confirmed that attackers gained limited access to the county network and to data maintained within it.
The public evidence establishes June 26 as the detection and containment date, not necessarily the beginning of attacker access. The intrusion’s actual start, duration and path into the environment remain unknown.
Operational significance
DysruptionHub’s published report documented outages affecting county servers, internet and phone lines. The Sheriff’s Office said its systems were offline and county offices could not make or receive calls. Delaware County Libraries reported that public computers and in-library catalogs were unavailable and asked patrons to bring library cards for checkout.
Later KYW Newsradio reporting quoted the county communications director saying phone systems, internet access, internal servers and financial software had been down. Systems were restored in stages while the investigation continued. The county used alternate procedures to keep services available, but normal staff and public access was restricted.
Disclosure posture
The county initially described the disruption as a network or provider outage before publicly confirming unauthorized activity on July 2. Its July 10 release carried an “all network systems” restoration headline, but the body said only internal systems were fully operational and that external systems serving residents were still being restored. The distinction matters because later reporting documented continuing impacts rather than a complete July 10 recovery.
Current status
On July 17, KYW reported that the county was still working to restore systems fully. A 6abc report the next day said most critical systems, including court, district attorney and sheriff systems, were back online but libraries remained affected. At the July 26 cutoff, the county’s official website still displayed an “Internet Outage” banner stating that non-emergency phones were operational but some network issues might persist. No later official all-clear was found.
Confidence and uncertainty
Cyber and operational-impact confidence are high because Delaware County directly confirmed limited unauthorized access and documented its defensive shutdown and recovery. Data confidentiality was affected at least at the access level, and data availability was impaired while county systems were offline. The county has not said whether information was copied, removed, altered, destroyed or exposed outside its network.
The public record does not establish ransomware, encryption, an extortion demand, payment or a named threat actor. 6abc cited unnamed sources saying no ransom had been paid as of July 18, but that does not establish whether a demand was made or whether the incident involved ransomware.
Analytic gaps
The reviewed evidence does not identify the initial-access vector, exploited vulnerability, compromised accounts, malware or tools, attacker dwell time, affected hosts or persistence. The scope and categories of accessed data, any exfiltration, affected-person count, notification obligations, final recovery date and investigative conclusions also remain unresolved.
Organizations involved
Delaware County, Pennsylvania

Locations
Organization type
Critical infrastructure
Impacted locations
Sources
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
Delaware County said unauthorized activity disrupted its network beginning June 26, prompting a shutdown while phones, servers and public services were affected. The county initially described the event as an outage before acknowledging intrusion attempts.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
Delaware County said unauthorized activity had disrupted its network since June 26 and that it shut down network access to protect sensitive information and critical systems while responding to intrusion attempts.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
The county described a sophisticated cybercriminal attack and confirmed limited access to its network and county-maintained data. It said internal network systems were fully operational on July 10, while external systems serving residents were still being restored and the data-risk investigation continued.
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
KYW reported that Delaware County was still restoring systems on July 17. County communications director Mike Connolly said phone systems, internet access, internal servers and financial software had been down; systems were returning in stages and the investigation continued.
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
6abc reported on July 18 that most critical systems, including court, district attorney and sheriff systems, were back online but libraries remained affected and the full scope was still under investigation. Unnamed sources said no ransom had been paid at that point.
- Type: Operational Update
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
The county homepage displayed an “Internet Outage” banner on July 26 stating that non-emergency county phones were operational again but that some network issues might persist.