Skip to content

Douglas County Sheriff's Office Network Disruption

Summary

Douglas County Sheriff's Office logo

Suspicious computer-system activity prompted the Douglas County Sheriff’s Office in Kansas to disconnect systems in August 2026, disrupting inmate reports, fingerprint scheduling and shared records access at Lawrence Police. Public inmate-report and fingerprint-scheduling interfaces were available by Sept. 26, but full shared-system recovery was not confirmed. A former Eudora IT administrator alleged ransomware and a connection to Eudora’s same-day incident; officials have not confirmed either.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Intermittent service disruption

    Services or systems experienced recurring, unstable, or temporary periods of unavailability.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Scheduling disruption

    Appointment, booking, reservation, dispatch, staffing, or other scheduling functions were unavailable or impaired.

  • Public safety operations disrupted

    Police, fire, emergency medical, corrections, emergency management, or other public-safety operations were materially affected.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Downstream organization impact

    The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that the Douglas County Sheriff’s Office in Kansas experienced a confirmed cyber incident involving suspicious activity in its computer environment. The office told the Lawrence Journal-World on Aug. 14 that it had identified suspicious activity on certain systems and launched an investigation. The office later said it disconnected systems after detecting the activity, preventing connectivity to those systems.

The specific cyber mechanism remains unknown. The sheriff’s office has not confirmed malware, ransomware, credential compromise, vulnerability exploitation, unauthorized data access or data theft. A stable leak-site claim or other named-actor attribution has not been identified.

Operational significance

The sheriff’s official website documented the earliest known public impact on Aug. 11. Its homepage said technical issues were preventing inmate reports and fingerprint scheduling and that the affected services were offline until further notice. Page metadata and contemporaneous reporting establish that those services were unavailable no later than Aug. 11, but they do not establish when the underlying suspicious activity began.

The disruption extended beyond public-facing sheriff services. The Journal-World reported Sept. 3 that Lawrence Police had remained disconnected from the shared Spillman system and network since Aug. 11. Officers told a court they could not access reports, and the department said it could not search its records-management system for reports written from Aug. 15, 2014, through Aug. 12, 2026. Officers continued writing and filing reports internally, and dispatch remained available.

The incident therefore caused internal-system, network, records-access, records-processing and scheduling disruptions, along with manual workarounds and downstream effects at Lawrence Police. Officials said 911, emergency response and dispatch remained functional. The evidence supports a material but bounded public-safety disruption rather than a loss of emergency-response capability.

Confidence and uncertainty

Confidence is high that the cyber investigation and operational disruption occurred because the sheriff’s office acknowledged suspicious activity and disconnection of systems, its website documented unavailable public services, and Lawrence Police described continuing loss of shared-system access. Data availability was affected because authorized users could not access historical reports. Whether information was viewed, copied or removed remains unresolved.

Ransomware, extortion and attribution remain unresolved. The sheriff’s office and City of Eudora declined to confirm or deny ransomware, and name- and domain-based searches found no stable leak-site claim, ransom demand or named threat actor connected to the Douglas County incident. Negative search results do not establish that no claim exists.

Disclosure posture

The sheriff’s Aug. 11 notice described technical issues and documented service effects without identifying a cyber cause. The office publicly acknowledged suspicious computer-system activity on Aug. 14, making that the first located cyber-specific disclosure and cyber-evidence date. Officials later disclosed the precautionary system disconnection but continued to withhold investigative details and a determination about personal-information exposure.

Current status

The Lawrence Journal-World’s Sept. 14 report described continuing records and video-access effects at agencies using the shared environment. Former Eudora IT administrator Andrew Krulik alleged ransomware, a ransom note and encrypted Eudora police files, and said the incident spread through the VPN connecting Eudora police to the sheriff’s office. Officials declined to confirm his account or the relationship between the incidents. His allegation does not independently establish ransomware deployment in the sheriff’s environment.

By Sept. 26, the sheriff’s homepage no longer displayed the earlier service-outage notice. The inmate-report service offered new booking, custody and bond reports; our check loaded the booking-report interface. The fingerprint scheduler also loaded an appointment calendar. These observations establish restored public access to those channels, not the precise restoration date or complete recovery of shared Spillman and historical records access. No final all-system restoration statement was located. Sept. 14 remains the latest supported operational-impact observation. With no newer dated impact or complete restoration established by Sept. 28, the incident is presumed active under the registry’s 14-day lifecycle rule.

Analytic gaps

The public record does not establish when the underlying suspicious activity began, the initial access vector, compromised accounts or hosts, malware family, persistence, encryption, exfiltration, affected data categories, ransom demand, vendor role, recovery method or incident-response cost. It also does not establish when sheriff and Lawrence Police access will be restored, whether notification obligations will arise or whether the Douglas County and Eudora incidents share a cause, infrastructure or actor.

Organizations involved

Impacted locations

Sources

Suspicious activity disrupts Douglas County sheriff's online services in Kansas

We reported that suspicious computer-system activity disrupted online inmate reports and fingerprint scheduling while 911 and emergency response remained functional. Our Aug. 26 review found both public services still listed as offline, with no restoration timetable, and the sheriff’s office did not respond to our questions by publication time.

Douglas County Sheriff's Office service outage notice

Historical Aug11 notice documented offline inmate reports and fingerprint scheduling, still seen Sept2. On Sept26 the homepage no longer displayed that notice and instead linked report and scheduling services.

Archive platform: Internet ArchiveArchived: Historical archive · not yet verifiedView archived copy
'Suspicious activity' disrupts computer system in Douglas County Sheriff's Office; some features now unavailable to public

The Journal-World reported that the jail booking log and other sheriff website features had been offline for days. The sheriff’s office said it identified suspicious activity on certain computer systems, launched an investigation and expected intermittent outages, while 911, emergency response and other county systems remained functional.

Archive platform: Archive.todayArchived: Historical archive · not yet verifiedView archived copy
Douglas County Sheriff's Office investigating after suspicious activity found on network

KCTV reported that the sheriff’s office detected suspicious activity on its computer systems and was investigating the nature and scope. The office said it was the only county office affected and that 911, emergency response and other public-safety services were not disrupted.

County says sharing information about 'suspicious activity' in sheriff's computer system would 'jeopardize public safety'

The sheriff’s office said its investigation was continuing and that certain systems and services had experienced intermittent outages, with some services potentially delayed. Officials said 911, emergency response and all public-safety services were fully functional and declined to confirm ransomware, data exposure or email impact.

Archive platform: Archive.todayArchived: Historical archive · not yet verifiedView archived copy
City of Eudora and sheriff's office won't say whether cyberattacks on same day are related; it's still unclear whether personal data exposed

The Journal-World reported that the sheriff’s office disconnected systems after detecting suspicious activity. Lawrence Police said it had remained disconnected from the shared Spillman system and network since Aug. 11, lacked access to historical reports and records searches, and was writing and filing reports internally while dispatch continued. Eudora’s city manager separately confirmed an Aug. 11 network security incident, but no official confirmed a connection between the incidents.

Archive platform: Archive.todayArchived: Historical archive · not yet verifiedView archived copy
Eudora’s just-terminated IT administrator says foreign ransomware is behind ‘big mess’ with city’s and sheriff’s computer systems

The Lawrence Journal-World reported Sept. 14 that a former Eudora IT administrator attributed the disruption to foreign ransomware, a ransom note and encrypted files; officials declined to confirm the claim.

Police

The City of Lawrence identifies the Lawrence Police Department as its municipal police agency and lists patrol, investigations, records, evidence and other law-enforcement functions.

DGSO Fingerprint Scheduler

Our Sept26 browser check loaded the official appointment calendar with selectable dates. No appointment was submitted.

DGSO Inmate Reports

The official page offers WARP booking, custody and bond reports; our Sept26 browser check loaded the booking-report interface.

See something that needs correction?

Signed-in members can report an error, update, or missing source.