Skip to content

Guam cyber incident disrupts government websites

Summary

Government of Guam logo

The Government of Guam activated its cyber response on May 2, 2026, after exploitation of the critical cPanel authentication-bypass flaw CVE-2026-41940 affected government-hosted websites. Public access to agency websites and online materials was disrupted, and the Bureau of Statistics and Plans was still rebuilding files and embedded content on August 2.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Website unavailable

    A public-facing website was unavailable, disabled, or inaccessible.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub’s published report documented that multiple Government of Guam websites were disrupted during a widespread cyber incident affecting cPanel-hosted systems. The Guam Homeland Security and Office of Civil Defense announcement said the territorial government activated its cyber incident response on May 2, 2026, while investigating exploitation of a critical zero-day vulnerability affecting cPanel and WebHost Manager.

The vendor later identified the flaw as CVE-2026-41940, a critical authentication vulnerability in the cPanel & WHM session-management layer. cPanel said a specially crafted request could cause an unauthenticated session to be treated as authenticated, granting access without valid credentials. DysruptionHub assesses with high confidence that successful exploitation of this vulnerability compromised internet-facing web-hosting infrastructure used by Government of Guam agencies.

Operational significance

The incident affected public access to government information and online administrative materials. The Bureau of Statistics and Plans said its website experienced service disruption, requiring residents to use Google Drive, email and in-person alternatives to review planning documents and submit public comments. This created a direct workaround burden for residents and agency staff even though emergency operations were reported as available.

The impact persisted beyond the initial outage. BSP’s current website notice says most file downloads and embedded content could not be restored from the compromised site and that staff are securely re-uploading files, datasets, reports and media. The confirmed data effect is unavailability of public materials; the reviewed sources do not establish whether information was copied or exposed.

Disclosure posture

The Government of Guam publicly acknowledged the incident, linked it to a globally exploited cPanel vulnerability and activated a coordinated response. Agency notices then documented practical service effects and alternative access methods. These disclosures provide organization-confirmed evidence for both the cyber event and the resulting disruption.

The public record does not identify which attacker exploited the vulnerability, whether all affected websites shared a server or hosting provider, or whether unauthorized access extended beyond website infrastructure. Government statements also did not confirm that personal information, credentials, email, databases or internal networks were accessed.

Current status

The incident remains active. On August 2, BSP’s official site still said the agency was restoring its website and securely re-uploading files, datasets and media that could not be restored from the compromised site. No later government-wide all-clear or completed restoration notice was found.

Confidence and uncertainty

Confidence is high in vulnerability exploitation because the territorial government directly connected its response to the cPanel zero-day and cPanel’s vendor analysis identifies the affected vulnerability and access condition. Confidence is also high that public website services, downloads and access to online records were disrupted.

Ransomware remains unresolved. The Government of Guam said encryption and ransomware-type activity were among worst-case scenarios under review, and broader exploitation of CVE-2026-41940 included ransomware activity elsewhere. The reviewed Guam sources do not confirm encryption, a ransom note, payment demand, leak threat or data-theft extortion. No named actor has been publicly attributed.

Analytic gaps

The reviewed sources do not establish the complete affected-agency list, hosting architecture, initial exploitation time, attacker identity, persistence mechanism, affected accounts, accessed databases, email impact or whether credentials were compromised. They also do not quantify the unavailable or unrecoverable files, establish whether information was copied or exposed, or provide a final government-wide restoration date.

Organizations involved

Impacted locations

Sources

2020 Island Areas Censuses: Guam

Official 2020 population and housing tables for Guam, its municipalities and census-designated places.

About Guam

Official territorial tourism profile describing Guam’s location, landscape, culture and visitor economy.

Hagåtña

Official village profile describing Hagåtña’s geography, history, government functions and commercial activity.

Guam cyber incident disrupts government websites

DysruptionHub reported that Government of Guam websites were disrupted during a widespread cyber incident involving cPanel-hosted systems. Officials activated a territorial cyber response while agencies worked to restore public-facing websites and online resources.

Government of Guam Activates Cyber Incident Response; Global Vulnerability Under Investigation

The Government of Guam activated its cyber incident response after identifying a widespread incident linked to a critical vulnerability affecting cPanel-hosted websites. Officials said response teams were investigating and securing affected government systems while essential and emergency operations remained available.

Bureau of Statistics and Plans Updates Public Comment Procedures

The Bureau of Statistics and Plans said its website was experiencing service disruption because of the widespread cPanel cyber incident. It directed residents to Google Drive, email, and in-person alternatives so public-comment access and submissions could continue.

Bureau of Statistics and Plans Website Restoration Update

BSP’s current site-wide notice says most file downloads and embedded content could not be restored after the cPanel compromise. The agency is still restoring the site and securely re-uploading files, datasets, reports and media, including public planning materials.

CVE-2026-41940: Response, Actions and Next Steps

cPanel identified CVE-2026-41940 as a critical authentication vulnerability in the cPanel & WHM session-management layer. A specially crafted request could cause an unauthenticated session to be treated as authenticated and grant access without valid credentials. Updates were released April 28, and CISA added the flaw to its Known Exploited Vulnerabilities catalog May 1.

About the Guam Bureau of Statistics and Plans

The Bureau describes its mission as coordinating plans, policies and programs; advising the governor; supporting balanced economic, social, environmental and physical development; making government information available for planning; and producing timely statistical indicators.

Guam

The Department of the Interior describes Guam as a United States territory and states that the Organic Act of 1950 conferred U.S. citizenship on Guamanians and established the territorial government.

Official Portal for the Island of Guam

The official portal provides a directory of Government of Guam agencies and resident services covering taxes, business registration, motor vehicles, voting, licenses, forms, laws, marriage licenses and vital records.

See something that needs correction?

Signed-in members can report an error, update, or missing source.