Guam cyber incident disrupts government websites
Summary
The Government of Guam’s response to exploitation of CVE-2026-41940 remained in active recovery August 10. The Bureau of Statistics and Plans still reported unavailable downloads and embedded content while staff re-uploaded files, data sets and media; no government-wide all-clear, confirmed data theft, ransomware finding or actor attribution was found.
Key facts
Timeline
-
First public signal:
?
Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity. -
First public cyber evidence:
?
Earliest credible public information connecting the incident or disruption to malicious cyber activity. -
Official cyber disclosure:
?
First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related. -
Last impact seen:
?
Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
Primary victim organization
Impacted locations
Organization types
Critical infrastructure sector
DysruptionHub coverage
Incident characteristics
Assessments
DD-CIT assessment
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Attack mechanisms
-
Vulnerability exploitation
Exploitation of a software or hardware vulnerability to gain unauthorized access or execute malicious actions.
-
Unauthorized access
Unauthorized access to systems, accounts, networks, or data.
Data impacts
-
Data unavailable
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Operational impacts
-
Website unavailable
A public-facing website was unavailable, disabled, or inaccessible.
-
Online portal unavailable
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
-
Records access disruption
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
-
Government services disrupted
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
-
Alternate service channel required
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
-
Customer or public access restricted
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Extortion indicators
-
No known extortion indicator
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
Incident narrative
Analyst assessment
DysruptionHub assesses with high confidence that exploitation of the critical cPanel authentication-bypass flaw CVE-2026-41940 compromised internet-facing web-hosting infrastructure used by Government of Guam agencies. The Guam Homeland Security and Office of Civil Defense announcement said the territorial government activated its cyber response May 2, 2026, after identifying a widespread incident affecting cPanel-hosted websites.
The vendor’s security update said a specially crafted request could cause an unauthenticated session to be treated as authenticated. The public record supports vulnerability exploitation and unauthorized access, but it does not identify the attacker or establish access beyond affected website infrastructure.
Operational significance
The incident disrupted public access to government websites, downloads and online administrative material. The Bureau of Statistics and Plans directed residents to Google Drive, email and in-person alternatives for planning documents and public comments, creating workarounds for residents and staff while essential and emergency operations remained available.
BSP’s current website notice says downloads and embedded content remain temporarily unavailable and that the agency is restoring the site and re-uploading files, data sets, reports and media. The established data effect is unavailability; the reviewed sources do not show whether information was copied, exposed or altered.
Disclosure posture
The Government of Guam directly acknowledged the incident, linked its response to exploitation of a critical cPanel vulnerability and documented practical service effects. The government has not published a complete affected-agency list, final technical report or government-wide restoration notice.
Current status
The incident remained active August 10. BSP’s restoration notice was still live and continued to describe unavailable content and ongoing re-upload work. No later government-wide all-clear was found.
Confidence and uncertainty
Confidence is high in both malicious exploitation and operational disruption because the territorial government linked the response to the cPanel vulnerability and agencies documented unavailable websites and public materials. Ransomware, data theft and attribution remain unresolved: no reviewed Guam source confirms encryption, a ransom demand, payment, leak activity or a responsible actor.
Analytic gaps
The public record does not establish the complete affected-agency list, hosting architecture, initial exploitation time, attacker identity, persistence, affected accounts, database access, email impact or credential compromise. It also does not quantify unrecoverable material or provide a final government-wide restoration date.
Organizations involved
Guam Bureau of Statistics and Plans

Locations
Organization type
Critical infrastructure
Impacted locations
Sources
DysruptionHub reported that Government of Guam websites were disrupted during a widespread cyber incident involving cPanel-hosted systems. Officials activated a territorial cyber response while agencies worked to restore public-facing websites and online resources.
The Government of Guam activated its cyber incident response after identifying a widespread incident linked to a critical vulnerability affecting cPanel-hosted websites. Officials said response teams were investigating and securing affected government systems while essential and emergency operations remained available.
The Bureau of Statistics and Plans said its website was experiencing service disruption because of the widespread cPanel cyber incident. It directed residents to Google Drive, email, and in-person alternatives so public-comment access and submissions could continue.
cPanel identified CVE-2026-41940 as a critical authentication vulnerability in the cPanel & WHM session-management layer. A specially crafted request could cause an unauthenticated session to be treated as authenticated and grant access without valid credentials. Updates were released April 28, and CISA added the flaw to its Known Exploited Vulnerabilities catalog May 1.
BSP’s official restoration notice remained live August 10. It said downloads and embedded content were temporarily unavailable and that the agency was restoring the site and securely re-uploading files, data sets, reports and media after the cPanel compromise.
See something that needs correction?
Signed-in members can report an error, update, or missing source.