Delaware County, Pennsylvania

Delaware County, Pennsylvania, detected anomalous network activity June 26, 2026, and took its network offline after remote attackers accessed the network and county-maintained data, disrupting phones, servers, financial software, libraries and other public services. The county did not publicly acknowledge cyber involvement until July 2; an earlier Sheriff’s Office explanation that called the outage a provider disruption was inconsistent with the county’s later account of detecting and containing the intrusion June 26. The county restored operations using secure backups, while potential exposure of sensitive data remains under review.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Unauthorized access to systems, accounts, networks, or data.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
A specific application or software platform became unavailable or unusable.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
Police, fire, emergency medical, corrections, emergency management, or other public-safety operations were materially affected.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Services continued but with longer processing, response, delivery, or completion times.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
DysruptionHub assesses with high confidence that Delaware County, Pennsylvania, experienced a malicious network intrusion that disrupted government services. The county’s July 2 statement said it identified unauthorized activity June 26 and shut down network access to protect sensitive information and critical systems. A July 10 update characterized the activity as a sophisticated cybercriminal attack and confirmed limited access to the county network and county-maintained data.
County Executive Director Barbara O’Malley later said managed detection alerts identified anomalous network activity June 26 and that forensic investigators determined attackers gained remote access that day. She said investigators found no evidence of phishing or unauthorized access to the county email system and no further unauthorized activity after the county secured its network June 26. The specific remote-access method remains unknown.
Our report documented outages affecting county servers, internet and phone lines. The Sheriff’s Office said its systems were offline and county offices could not make or receive calls. Delaware County Libraries reported that public computers and in-library catalogs were unavailable and asked patrons to bring library cards for checkout.
KYW Newsradio quoted the county communications director saying phone systems, internet access, internal servers and financial software had been down. Departments used alternate procedures, including paper workflows, to maintain services while systems returned in stages.
The county publicly described the disruption as a network outage beginning June 26. The Sheriff’s Office later said county IT and communications personnel were working to resolve what it called a `provider disruption`. When we asked July 1 whether the event was being investigated as a cybersecurity incident or whether cybersecurity involvement had been ruled out, the county did not answer that question.
The county acknowledged July 2 that unauthorized activity had disrupted its network and that it deliberately shut down access in response to intrusion attempts. It disclosed July 10 that attackers had gained limited access to the county network and county-maintained data. O’Malley later said managed detection alerts identified anomalous activity June 26 and officials took the network offline that day.
That chronology makes the provider-disruption explanation more than an incomplete early description. It pointed the public toward an external service cause that was inconsistent with the county’s later account of what officials detected and why they shut down the network June 26. The public record does not establish who originated or approved the Sheriff’s Office wording, what information the office had received or whether anyone intended to mislead.
The July 2 disclosure remains the earliest dated concrete public cyber signal. June 26 is the detection and containment date, not the public cyber-evidence date.
The incident is resolved operationally. In an Aug. 3 statement, the county said it had fully restored operations and used secure backup data to minimize the impact. O’Malley later said the county reset credentials for all network account holders and rebuilt systems and devices from secure, uninfected backups.
The resolved status marks the end of documented service impact, not the end of forensic, legal or data-risk work. The county was still reviewing which data attackers accessed and said it would notify affected people if required by law.
Cyber and operational-impact confidence are high because Delaware County directly confirmed remote unauthorized access, defensive shutdown and recovery. Data confidentiality was affected at least at the access level, and data availability was impaired while systems were offline. The county has not said whether information was copied, removed, altered or exposed outside its network.
The public record does not establish ransomware, encryption, an extortion demand, payment or a named threat actor. O’Malley said the county restored its network and data without relying on a decryption key or other outside tools, but that statement does not establish that encryption occurred. The county’s 2020 ransomware incident explains its backup improvements but does not establish the mechanism or attribution of the 2026 intrusion.
The public record does not identify the remote-access method, exploited vulnerability, compromised account, malware or tools, attacker dwell time, affected hosts or persistence. The accessed-data categories, any exfiltration, affected-person count, notification obligations and actor attribution also remain unresolved.

Our reporting documented that the county and Sheriff’s Office initially described the event as a network outage and provider disruption. The county did not answer a July 1 question about cybersecurity involvement, then said July 2 that unauthorized activity disrupted the network and that it shut down access in response to intrusion attempts.
Delaware County said unauthorized activity had disrupted its network since June 26 and that it shut down network access to protect sensitive information and critical systems while responding to intrusion attempts.
The county described a sophisticated cybercriminal attack and confirmed limited access to its network and county-maintained data. It said internal network systems were fully operational on July 10, while external systems serving residents were still being restored and the data-risk investigation continued.
KYW reported that Delaware County was still restoring systems on July 17. County communications director Mike Connolly said phone systems, internet access, internal servers and financial software had been down; systems were returning in stages and the investigation continued.
6abc reported on July 18 that most critical systems, including court, district attorney and sheriff systems, were back online but libraries remained affected and the full scope was still under investigation. Unnamed sources said no ransom had been paid at that point.
Delaware County said it had fully restored county operations and used secure backup data to minimize the impact. The county said attackers accessed its network and county-maintained data while the scope of risk to sensitive information remained under investigation.
The Delco Times reported that county officials detected the intrusion through managed detection alerts June 26 and determined attackers gained remote network access that day. Investigators found no phishing or unauthorized email access. The county reset all network credentials and rebuilt systems and devices from secure, uninfected backups.
On August 18, the county homepage presented ordinary service links, public access, current meetings and county news without the prior Internet Outage banner or another continuing incident warning.
Signed-in members can report an error, update, or missing source.