Douglas County Sheriff's Office

Suspicious computer-system activity prompted the Douglas County Sheriff’s Office in Kansas to disconnect systems in August 2026, disrupting inmate reports, fingerprint scheduling and shared records access at Lawrence Police. Public inmate-report and fingerprint-scheduling interfaces were available by Sept. 26, but full shared-system recovery was not confirmed. A former Eudora IT administrator alleged ransomware and a connection to Eudora’s same-day incident; officials have not confirmed either.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Services or systems experienced recurring, unstable, or temporary periods of unavailability.
Internal or external network connectivity was unavailable or materially impaired.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.
Appointment, booking, reservation, dispatch, staffing, or other scheduling functions were unavailable or impaired.
Police, fire, emergency medical, corrections, emergency management, or other public-safety operations were materially affected.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Services continued but with longer processing, response, delivery, or completion times.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
DysruptionHub assesses with high confidence that the Douglas County Sheriff’s Office in Kansas experienced a confirmed cyber incident involving suspicious activity in its computer environment. The office told the Lawrence Journal-World on Aug. 14 that it had identified suspicious activity on certain systems and launched an investigation. The office later said it disconnected systems after detecting the activity, preventing connectivity to those systems.
The specific cyber mechanism remains unknown. The sheriff’s office has not confirmed malware, ransomware, credential compromise, vulnerability exploitation, unauthorized data access or data theft. A stable leak-site claim or other named-actor attribution has not been identified.
The sheriff’s official website documented the earliest known public impact on Aug. 11. Its homepage said technical issues were preventing inmate reports and fingerprint scheduling and that the affected services were offline until further notice. Page metadata and contemporaneous reporting establish that those services were unavailable no later than Aug. 11, but they do not establish when the underlying suspicious activity began.
The disruption extended beyond public-facing sheriff services. The Journal-World reported Sept. 3 that Lawrence Police had remained disconnected from the shared Spillman system and network since Aug. 11. Officers told a court they could not access reports, and the department said it could not search its records-management system for reports written from Aug. 15, 2014, through Aug. 12, 2026. Officers continued writing and filing reports internally, and dispatch remained available.
The incident therefore caused internal-system, network, records-access, records-processing and scheduling disruptions, along with manual workarounds and downstream effects at Lawrence Police. Officials said 911, emergency response and dispatch remained functional. The evidence supports a material but bounded public-safety disruption rather than a loss of emergency-response capability.
Confidence is high that the cyber investigation and operational disruption occurred because the sheriff’s office acknowledged suspicious activity and disconnection of systems, its website documented unavailable public services, and Lawrence Police described continuing loss of shared-system access. Data availability was affected because authorized users could not access historical reports. Whether information was viewed, copied or removed remains unresolved.
Ransomware, extortion and attribution remain unresolved. The sheriff’s office and City of Eudora declined to confirm or deny ransomware, and name- and domain-based searches found no stable leak-site claim, ransom demand or named threat actor connected to the Douglas County incident. Negative search results do not establish that no claim exists.
The sheriff’s Aug. 11 notice described technical issues and documented service effects without identifying a cyber cause. The office publicly acknowledged suspicious computer-system activity on Aug. 14, making that the first located cyber-specific disclosure and cyber-evidence date. Officials later disclosed the precautionary system disconnection but continued to withhold investigative details and a determination about personal-information exposure.
The Lawrence Journal-World’s Sept. 14 report described continuing records and video-access effects at agencies using the shared environment. Former Eudora IT administrator Andrew Krulik alleged ransomware, a ransom note and encrypted Eudora police files, and said the incident spread through the VPN connecting Eudora police to the sheriff’s office. Officials declined to confirm his account or the relationship between the incidents. His allegation does not independently establish ransomware deployment in the sheriff’s environment.
By Sept. 26, the sheriff’s homepage no longer displayed the earlier service-outage notice. The inmate-report service offered new booking, custody and bond reports; our check loaded the booking-report interface. The fingerprint scheduler also loaded an appointment calendar. These observations establish restored public access to those channels, not the precise restoration date or complete recovery of shared Spillman and historical records access. No final all-system restoration statement was located. Sept. 14 remains the latest supported operational-impact observation. With no newer dated impact or complete restoration established by Sept. 28, the incident is presumed active under the registry’s 14-day lifecycle rule.
The public record does not establish when the underlying suspicious activity began, the initial access vector, compromised accounts or hosts, malware family, persistence, encryption, exfiltration, affected data categories, ransom demand, vendor role, recovery method or incident-response cost. It also does not establish when sheriff and Lawrence Police access will be restored, whether notification obligations will arise or whether the Douglas County and Eudora incidents share a cause, infrastructure or actor.


We reported that suspicious computer-system activity disrupted online inmate reports and fingerprint scheduling while 911 and emergency response remained functional. Our Aug. 26 review found both public services still listed as offline, with no restoration timetable, and the sheriff’s office did not respond to our questions by publication time.
Historical Aug11 notice documented offline inmate reports and fingerprint scheduling, still seen Sept2. On Sept26 the homepage no longer displayed that notice and instead linked report and scheduling services.
The Journal-World reported that the jail booking log and other sheriff website features had been offline for days. The sheriff’s office said it identified suspicious activity on certain computer systems, launched an investigation and expected intermittent outages, while 911, emergency response and other county systems remained functional.
KCTV reported that the sheriff’s office detected suspicious activity on its computer systems and was investigating the nature and scope. The office said it was the only county office affected and that 911, emergency response and other public-safety services were not disrupted.
The sheriff’s office said its investigation was continuing and that certain systems and services had experienced intermittent outages, with some services potentially delayed. Officials said 911, emergency response and all public-safety services were fully functional and declined to confirm ransomware, data exposure or email impact.
The Journal-World reported that the sheriff’s office disconnected systems after detecting suspicious activity. Lawrence Police said it had remained disconnected from the shared Spillman system and network since Aug. 11, lacked access to historical reports and records searches, and was writing and filing reports internally while dispatch continued. Eudora’s city manager separately confirmed an Aug. 11 network security incident, but no official confirmed a connection between the incidents.
The Lawrence Journal-World reported Sept. 14 that a former Eudora IT administrator attributed the disruption to foreign ransomware, a ransom note and encrypted files; officials declined to confirm the claim.
The City of Lawrence identifies the Lawrence Police Department as its municipal police agency and lists patrol, investigations, records, evidence and other law-enforcement functions.
Our Sept26 browser check loaded the official appointment calendar with selectable dates. No appointment was submitted.
The official page offers WARP booking, custody and bond reports; our Sept26 browser check loaded the booking-report interface.
Signed-in members can report an error, update, or missing source.