Skip to content

Guam cyber incident disrupts government websites

Summary

Government of Guam logo

Exploitation of CVE-2026-41940 compromised Government of Guam web infrastructure and disrupted access to agency websites, downloads and public documents beginning in May 2026. The Bureau of Statistics and Plans later removed its restoration warning and repopulated report and data pages; the incident is presumed resolved because no territorial government all-clear establishes the exact recovery date.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Website unavailable

    A public-facing website was unavailable, disabled, or inaccessible.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that exploitation of the critical cPanel authentication-bypass flaw CVE-2026-41940 compromised internet-facing web-hosting infrastructure used by Government of Guam agencies. The Guam Homeland Security and Office of Civil Defense announcement said the territorial government activated its cyber response May 2, 2026, after identifying a widespread incident affecting cPanel-hosted websites.

The vendor’s security update said a specially crafted request could cause an unauthenticated session to be treated as authenticated. The public record supports vulnerability exploitation and unauthorized access, but it does not identify the attacker or establish access beyond affected website infrastructure.

Operational significance

The incident disrupted public access to government websites, downloads and online administrative material. The Bureau of Statistics and Plans directed residents to Google Drive, email and in-person alternatives for planning documents and public comments, creating workarounds for residents and staff while essential and emergency operations remained available.

BSP later reported that downloads and embedded content were temporarily unavailable while it restored the site and re-uploaded files, data sets, reports and media. The established data effect is unavailability; the reviewed sources do not show whether information was copied, exposed or altered.

Disclosure posture

The Government of Guam directly acknowledged the incident, linked its response to exploitation of a critical cPanel vulnerability and documented practical service effects. The government has not published a complete affected-agency list, final technical report or government-wide restoration notice.

Current status

The incident is presumed resolved. August 10 was the date BSP’s undated restoration notice was observed, not the date of a new disruption or agency announcement. The notice still described unavailable content and ongoing re-upload work at that time, making August 10 the latest supported observation of operational impact.

By August 16, the warning no longer appeared on BSP’s home, about, reports or links pages. The reports catalog was populated with statistical, planning, census and coastal-management materials, and the home page linked recent reports and public notices. Those conditions are strong evidence of recovery, but they do not establish when every affected Government of Guam website was restored.

Confidence and uncertainty

Confidence is high in both malicious exploitation and operational disruption because the territorial government linked the response to the cPanel vulnerability and agencies documented unavailable websites and public materials. Confidence is medium that operational impact has ended because BSP’s restoration warning was removed and public materials are again available, but no government-wide all-clear provides a definitive closure date.

Ransomware, data theft and attribution remain unresolved. No reviewed Guam source confirms encryption, a ransom demand, payment, leak activity or a responsible actor. The government’s initial reference to worst-case scenarios under review did not confirm that those effects occurred.

Analytic gaps

The public record does not establish the complete affected-agency list, hosting architecture, initial exploitation time, attacker identity, persistence, affected accounts, database access, email impact or credential compromise. It also does not quantify unrecoverable material or provide a final government-wide restoration date.

Organizations involved

Impacted locations

Sources

Guam cyber incident disrupts government websites

DysruptionHub reported that Government of Guam websites were disrupted during a widespread cyber incident involving cPanel-hosted systems. Officials activated a territorial cyber response while agencies worked to restore public-facing websites and online resources.

Government of Guam Activates Cyber Incident Response; Global Vulnerability Under Investigation

The Government of Guam activated its cyber incident response after identifying a widespread incident linked to a critical vulnerability affecting cPanel-hosted websites. Officials said response teams were investigating and securing affected government systems while essential and emergency operations remained available.

Bureau of Statistics and Plans Updates Public Comment Procedures

The Bureau of Statistics and Plans said its website was experiencing service disruption because of the widespread cPanel cyber incident. It directed residents to Google Drive, email, and in-person alternatives so public-comment access and submissions could continue.

CVE-2026-41940: Response, Actions and Next Steps

cPanel identified CVE-2026-41940 as a critical authentication vulnerability in the cPanel & WHM session-management layer. A specially crafted request could cause an unauthenticated session to be treated as authenticated and grant access without valid credentials. Updates were released April 28, and CISA added the flaw to its Known Exploited Vulnerabilities catalog May 1.

Bureau of Statistics and Plans website status

BSP’s undated restoration warning was observed August 10, when it still described unavailable downloads and ongoing re-upload work. Direct retrieval August 16 found the warning removed from BSP’s home, about, reports and links pages, while recent reports and public notices were available.

Reports, Publications, and Data

BSP’s reports page was populated August 16 with links to statistical, planning, census, GIS and coastal-management publications. The prior website-restoration warning was no longer present on the reports page.

See something that needs correction?

Signed-in members can report an error, update, or missing source.