Skip to content

Fargo Park District ransomware disruption

Summary

Fargo Park District logo

Fargo Park District detected unusual network activity Oct. 27, 2025, and reported temporary phone, email and internal-system disruptions. Essential parks and programs remained open. A 2026 district board packet described a phishing-to-ransomware attack path and VPN disruption. The district later mailed notices to people whose information was in affected files.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Phishing

    The use of deceptive messages or websites to trick people into revealing information, transferring funds or executing malicious content.

  • Credential compromise

    Theft, exposure, or abuse of user or administrator credentials.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

Operational impacts

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Fargo Park District experienced a disruptive cybersecurity incident in October 2025, covered by our Dec. 5 article. The district’s official update confirms the Oct. 27 discovery and temporary phone, email and internal-system disruption. A 2026 board packet describes the October event as ransomware and records a path from phishing through a compromised Windows device and stolen domain administrator credentials to ransomware. The victim’s later July 13 update says it mailed notices to people whose information was in affected files.

Operational significance

The district said essential programs, services and facilities continued. Phones, email, internal systems and VPN access were interrupted, requiring restoration work; the reviewed sources do not establish an outage of park facilities or third-party registration systems.

Current status

District officials said phones and email had largely been restored by the December disclosure. The data review continued into 2026 and notices were mailed in July. No reviewed source gives an exact all-systems restoration date. This retrospective record is presumed resolved without claiming a final technical all-clear.

Confidence and uncertainty

The victim’s public statement establishes the operational disruption; the board packet supports ransomware classification. An Interlock victim listing is an external claim and is not independently verified as actor attribution or proof of data theft. The July notice supports affected-file exposure but details of data categories and count were not established in the reviewed update.

Analytic gaps

The precise phishing message or delivery channel, ransomware variant, actor identity, affected data categories, final affected-person count and complete restoration timeline remain unresolved.

Threat actor and claim

Listed as: Fargo Park DistrictSource: ransomware.liveDiscovered:

Claim details

Interlock listed Fargo Park District as a purported victim on its leak site, as recorded by ransomware.live and our Dec. 5 report. The district has confirmed an October ransomware incident but has not attributed it to Interlock or confirmed the listing’s allegations.

Organizations involved

Impacted location

  • Fargo, North Dakota

    The district is the Park District of the City of Fargo; the city represents its public service remit without implying every park or resident lost service.

    Fargo anchors the park district's administrative operations; no facility-specific outage is asserted.

Sources

Fargo Park District in North Dakota discloses October cyber incident

We reported that Fargo Park District disclosed its Oct. 27 network incident Dec. 5 after weeks of phone, email and internal-system problems, while an Interlock listing remained unverified.

Cybersecurity Event Update

The district says unusual network activity discovered Oct. 27 caused temporary phone, email and internal-system disruption; essential programs and facilities remained operational.

March 10, 2026 Fargo Park District board packet

District committee minutes in the board packet say October ransomware disrupted phones, systems and VPN and describe an attack path of phishing, a compromised Windows device and stolen domain administrator credentials.

Updates

The district says it mailed data-privacy notices July 13 to people whose information was determined to be in affected files.

See something that needs correction?

Signed-in members can report an error, update, or missing source.