Skip to content

Delaware County cyberattack disrupts county systems

Summary

Delaware County, Pennsylvania logo

Delaware County, Pennsylvania, detected anomalous network activity June 26, 2026, and took its network offline after remote attackers accessed the network and county-maintained data, disrupting phones, servers, financial software, libraries and other public services. The county did not publicly acknowledge cyber involvement until July 2; an earlier Sheriff’s Office explanation that called the outage a provider disruption was inconsistent with the county’s later account of detecting and containing the intrusion June 26. The county restored operations using secure backups, while potential exposure of sensitive data remains under review.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Public safety operations disrupted

    Police, fire, emergency medical, corrections, emergency management, or other public-safety operations were materially affected.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Delaware County, Pennsylvania, experienced a malicious network intrusion that disrupted government services. The county’s July 2 statement said it identified unauthorized activity June 26 and shut down network access to protect sensitive information and critical systems. A July 10 update characterized the activity as a sophisticated cybercriminal attack and confirmed limited access to the county network and county-maintained data.

County Executive Director Barbara O’Malley later said managed detection alerts identified anomalous network activity June 26 and that forensic investigators determined attackers gained remote access that day. She said investigators found no evidence of phishing or unauthorized access to the county email system and no further unauthorized activity after the county secured its network June 26. The specific remote-access method remains unknown.

Operational significance

Our report documented outages affecting county servers, internet and phone lines. The Sheriff’s Office said its systems were offline and county offices could not make or receive calls. Delaware County Libraries reported that public computers and in-library catalogs were unavailable and asked patrons to bring library cards for checkout.

KYW Newsradio quoted the county communications director saying phone systems, internet access, internal servers and financial software had been down. Departments used alternate procedures, including paper workflows, to maintain services while systems returned in stages.

Disclosure posture

The county publicly described the disruption as a network outage beginning June 26. The Sheriff’s Office later said county IT and communications personnel were working to resolve what it called a `provider disruption`. When we asked July 1 whether the event was being investigated as a cybersecurity incident or whether cybersecurity involvement had been ruled out, the county did not answer that question.

The county acknowledged July 2 that unauthorized activity had disrupted its network and that it deliberately shut down access in response to intrusion attempts. It disclosed July 10 that attackers had gained limited access to the county network and county-maintained data. O’Malley later said managed detection alerts identified anomalous activity June 26 and officials took the network offline that day.

That chronology makes the provider-disruption explanation more than an incomplete early description. It pointed the public toward an external service cause that was inconsistent with the county’s later account of what officials detected and why they shut down the network June 26. The public record does not establish who originated or approved the Sheriff’s Office wording, what information the office had received or whether anyone intended to mislead.

The July 2 disclosure remains the earliest dated concrete public cyber signal. June 26 is the detection and containment date, not the public cyber-evidence date.

Current status

The incident is resolved operationally. In an Aug. 3 statement, the county said it had fully restored operations and used secure backup data to minimize the impact. O’Malley later said the county reset credentials for all network account holders and rebuilt systems and devices from secure, uninfected backups.

The resolved status marks the end of documented service impact, not the end of forensic, legal or data-risk work. The county was still reviewing which data attackers accessed and said it would notify affected people if required by law.

Confidence and uncertainty

Cyber and operational-impact confidence are high because Delaware County directly confirmed remote unauthorized access, defensive shutdown and recovery. Data confidentiality was affected at least at the access level, and data availability was impaired while systems were offline. The county has not said whether information was copied, removed, altered or exposed outside its network.

The public record does not establish ransomware, encryption, an extortion demand, payment or a named threat actor. O’Malley said the county restored its network and data without relying on a decryption key or other outside tools, but that statement does not establish that encryption occurred. The county’s 2020 ransomware incident explains its backup improvements but does not establish the mechanism or attribution of the 2026 intrusion.

Analytic gaps

The public record does not identify the remote-access method, exploited vulnerability, compromised account, malware or tools, attacker dwell time, affected hosts or persistence. The accessed-data categories, any exfiltration, affected-person count, notification obligations and actor attribution also remain unresolved.

Organizations involved

Impacted locations

Sources

Delaware County investigates network intrusion

Our reporting documented that the county and Sheriff’s Office initially described the event as a network outage and provider disruption. The county did not answer a July 1 question about cybersecurity involvement, then said July 2 that unauthorized activity disrupted the network and that it shut down access in response to intrusion attempts.

Delaware County Statement on Network Outage

Delaware County said unauthorized activity had disrupted its network since June 26 and that it shut down network access to protect sensitive information and critical systems while responding to intrusion attempts.

Delaware County Provides Update on Network Disruption

The county described a sophisticated cybercriminal attack and confirmed limited access to its network and county-maintained data. It said internal network systems were fully operational on July 10, while external systems serving residents were still being restored and the data-risk investigation continued.

Delco still working to get systems fully back and running after June cyberattack

KYW reported that Delaware County was still restoring systems on July 17. County communications director Mike Connolly said phone systems, internet access, internal servers and financial software had been down; systems were returning in stages and the investigation continued.

Delaware County: Cyber-attack caused system outages

6abc reported on July 18 that most critical systems, including court, district attorney and sheriff systems, were back online but libraries remained affected and the full scope was still under investigation. Unnamed sources said no ransom had been paid at that point.

Delaware County Provides Update on Recent Cybercriminal Attack that Impacted County Systems

Delaware County said it had fully restored county operations and used secure backup data to minimize the impact. The county said attackers accessed its network and county-maintained data while the scope of risk to sensitive information remained under investigation.

Past hack helped Delaware County prepare for recent one

The Delco Times reported that county officials detected the intrusion through managed detection alerts June 26 and determined attackers gained remote network access that day. Investigators found no phishing or unauthorized email access. The county reset all network credentials and rebuilt systems and devices from secure, uninfected backups.

Delaware County current network-status banner

On August 18, the county homepage presented ordinary service links, public access, current meetings and county news without the prior Internet Outage banner or another continuing incident warning.

See something that needs correction?

Signed-in members can report an error, update, or missing source.