Skip to content

Deschutes Public Library cyberattack

Summary

Deschutes Public Library logo

Deschutes Public Library closed all branches Dec. 12-14, 2025, and took its website and in-building services offline after unauthorized access to older communications servers. A March 2026 library notice said some personal information was involved, revising the initial belief that patron and staff records were unaffected.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

Operational impacts

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Deschutes Public Library experienced unauthorized access and material service disruption in December 2025. Our Dec. 12 report described all-branch closures and a website shutdown. Oregon Public Broadcasting interviewed library director Todd Dunkelberg, who said an outsider had accessed older servers containing public-relations materials and that security alerts prompted the shutdown.

Operational significance

The library’s Dec. 12 notice confirms that it closed branches Dec. 12-14, shut book drops and lost website and email access; in-building circulation and Wi-Fi were also disrupted. Patrons could still use a separate catalog and Libby digital materials. The closures affected library service across its Deschutes County remit; this is not evidence that every resident experienced an outage.

Current status

A March 25, 2026 notification letter from the library says the security incident involved personal information and offered identity-protection services. This revises the preliminary belief that customer and staff records were unaffected. The categories and number of people affected have not been verified.

The director hoped to reopen for regular hours Dec. 15. The reviewed initial sources do not establish a confirmed final reopening or a full technical restoration date. Because no later operational disruption was documented in the reviewed material, this retrospective record is presumed resolved, without claiming a verified all-clear.

Confidence and uncertainty

The director’s first-hand account supports unauthorized access and disruption. He initially said the accessed servers contained communications materials and that customer and staff records were not believed to be compromised. The later notification confirms some personal information was involved, but the available evidence does not establish exactly whose records, which categories of information or whether files were taken. The attack mechanism remains unresolved.

Analytic gaps

Initial access, actor identity, full server scope, affected data categories and person count, and final restoration date remain unresolved.

Organizations involved

Impacted locations

  • Bend, Oregon

    Bend is the library's administrative and branch anchor; all branches across the district were closed.

  • Deschutes County, Oregon

    The countywide public library service area is represented because the public library district was affected; this does not assert every resident experienced an outage.

  • La Pine, Oregon

    The library's December 2025 notice said all branches closed; its La Pine branch was among the system locations.

  • Redmond, Oregon

    The library's December 2025 notice said all branches closed; its Redmond branch was among the system locations.

  • Sisters, Oregon

    The library's December 2025 notice said all branches closed; its Sisters branch was among the system locations.

  • Sunriver, Oregon

    The library's December 2025 notice said all branches closed; its Sunriver branch was among the system locations.

Sources

Oregon's Deschutes Public Library closes after data breach

We reported that all Deschutes Public Library branches closed Dec. 12-14 after a network security alert, while the website, circulation and in-building Wi-Fi were disrupted.

Deschutes County Library closed through Sunday following cyberattack

Library Director Todd Dunkelberg told OPB an unknown outsider accessed older servers containing public-relations materials; all branches were closed while an outside security firm investigated.

Deschutes Public Library Closure December 12–14, 2025

The library said all locations would close Dec. 12-14 because of network security issues. Its website, email and book drops were unavailable, while patrons could still use the separate catalog and Libby. The director hoped to reopen for regular hours Dec. 15.

Deschutes Public Library District notice of data security incident

The library’s March 25, 2026 notification letter states that a recent data security incident involved the recipient’s personal information and offers identity-protection services.

See something that needs correction?

Signed-in members can report an error, update, or missing source.