Delaware County, Pennsylvania

Delaware County, Pennsylvania, identified unauthorized intrusion attempts on June 26, 2026, and shut down network systems to protect sensitive information. Attackers gained limited access to the county network and data, while phones, servers, financial software, libraries and other public services were disrupted. On August 3, the county still warned that some network issues might persist.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Unauthorized access to systems, accounts, networks, or data.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
A specific application or software platform became unavailable or unusable.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
Police, fire, emergency medical, corrections, emergency management, or other public-safety operations were materially affected.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Services continued but with longer processing, response, delivery, or completion times.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
DysruptionHub assesses with high confidence that Delaware County, Pennsylvania, experienced a malicious network intrusion that caused material government-service disruption. The county’s July 2 statement said it identified unauthorized activity on June 26 and shut down network access to protect sensitive information and critical systems. A July 10 update characterized the activity as a sophisticated cybercriminal attack and confirmed that attackers gained limited access to the county network and to data maintained within it.
The public evidence establishes June 26 as the detection and containment date, not necessarily the beginning of attacker access. The intrusion’s actual start, duration and path into the environment remain unknown.
DysruptionHub’s published report documented outages affecting county servers, internet and phone lines. The Sheriff’s Office said its systems were offline and county offices could not make or receive calls. Delaware County Libraries reported that public computers and in-library catalogs were unavailable and asked patrons to bring library cards for checkout.
Later KYW Newsradio reporting quoted the county communications director saying phone systems, internet access, internal servers and financial software had been down. Systems were restored in stages while the investigation continued. The county used alternate procedures to keep services available, but normal staff and public access was restricted.
The county initially described the disruption as a network or provider outage before publicly confirming unauthorized activity on July 2. Its July 10 release carried an “all network systems” restoration headline, but the body said only internal systems were fully operational and that external systems serving residents were still being restored. The distinction matters because later reporting and the county’s continuing homepage notice documented unresolved impacts rather than a complete July 10 recovery.
The incident remains active. On August 3, the county’s official homepage still displayed an “Internet Outage” banner stating that non-emergency county phones were operational but some network issues might persist. That warning is the latest direct official evidence of continuing operational impact.
The county library website presented normal catalog, account and event functions on August 3, which is a credible recovery signal for library services. It does not supersede the countywide network notice or establish that every external and resident-facing system had been restored. No later official all-clear was identified.
Cyber and operational-impact confidence are high because Delaware County directly confirmed limited unauthorized access and documented its defensive shutdown and recovery. Data confidentiality was affected at least at the access level, and data availability was impaired while county systems were offline. The county has not said whether information was copied, removed, altered, destroyed or exposed outside its network.
The public record does not establish ransomware, encryption, an extortion demand, payment or a named threat actor. 6abc cited unnamed sources saying no ransom had been paid as of July 18, but that does not establish whether a demand was made or whether the incident involved ransomware.
The public record does not identify the initial-access vector, exploited vulnerability, compromised accounts, malware or tools, attacker dwell time, affected hosts or persistence. The scope and categories of accessed data, any exfiltration, affected-person count, notification obligations, final recovery date and investigative conclusions also remain unresolved.

Delaware County said unauthorized activity disrupted its network beginning June 26, prompting a shutdown while phones, servers and public services were affected. The county initially described the event as an outage before acknowledging intrusion attempts.
Delaware County said unauthorized activity had disrupted its network since June 26 and that it shut down network access to protect sensitive information and critical systems while responding to intrusion attempts.
The county described a sophisticated cybercriminal attack and confirmed limited access to its network and county-maintained data. It said internal network systems were fully operational on July 10, while external systems serving residents were still being restored and the data-risk investigation continued.
KYW reported that Delaware County was still restoring systems on July 17. County communications director Mike Connolly said phone systems, internet access, internal servers and financial software had been down; systems were returning in stages and the investigation continued.
6abc reported on July 18 that most critical systems, including court, district attorney and sheriff systems, were back online but libraries remained affected and the full scope was still under investigation. Unnamed sources said no ransom had been paid at that point.
The county homepage continued to display an “Internet Outage” banner on August 3 stating that non-emergency county phones were operational but that some network issues might persist.
Signed-in members can report an error, update, or missing source.