Skip to content

Guam cyber incident disrupts government websites

Summary

Government of Guam logo

The Government of Guam’s response to exploitation of CVE-2026-41940 remained in active recovery August 10. The Bureau of Statistics and Plans still reported unavailable downloads and embedded content while staff re-uploaded files, data sets and media; no government-wide all-clear, confirmed data theft, ransomware finding or actor attribution was found.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Website unavailable

    A public-facing website was unavailable, disabled, or inaccessible.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that exploitation of the critical cPanel authentication-bypass flaw CVE-2026-41940 compromised internet-facing web-hosting infrastructure used by Government of Guam agencies. The Guam Homeland Security and Office of Civil Defense announcement said the territorial government activated its cyber response May 2, 2026, after identifying a widespread incident affecting cPanel-hosted websites.

The vendor’s security update said a specially crafted request could cause an unauthenticated session to be treated as authenticated. The public record supports vulnerability exploitation and unauthorized access, but it does not identify the attacker or establish access beyond affected website infrastructure.

Operational significance

The incident disrupted public access to government websites, downloads and online administrative material. The Bureau of Statistics and Plans directed residents to Google Drive, email and in-person alternatives for planning documents and public comments, creating workarounds for residents and staff while essential and emergency operations remained available.

BSP’s current website notice says downloads and embedded content remain temporarily unavailable and that the agency is restoring the site and re-uploading files, data sets, reports and media. The established data effect is unavailability; the reviewed sources do not show whether information was copied, exposed or altered.

Disclosure posture

The Government of Guam directly acknowledged the incident, linked its response to exploitation of a critical cPanel vulnerability and documented practical service effects. The government has not published a complete affected-agency list, final technical report or government-wide restoration notice.

Current status

The incident remained active August 10. BSP’s restoration notice was still live and continued to describe unavailable content and ongoing re-upload work. No later government-wide all-clear was found.

Confidence and uncertainty

Confidence is high in both malicious exploitation and operational disruption because the territorial government linked the response to the cPanel vulnerability and agencies documented unavailable websites and public materials. Ransomware, data theft and attribution remain unresolved: no reviewed Guam source confirms encryption, a ransom demand, payment, leak activity or a responsible actor.

Analytic gaps

The public record does not establish the complete affected-agency list, hosting architecture, initial exploitation time, attacker identity, persistence, affected accounts, database access, email impact or credential compromise. It also does not quantify unrecoverable material or provide a final government-wide restoration date.

Organizations involved

Impacted locations

Sources

Guam cyber incident disrupts government websites

DysruptionHub reported that Government of Guam websites were disrupted during a widespread cyber incident involving cPanel-hosted systems. Officials activated a territorial cyber response while agencies worked to restore public-facing websites and online resources.

Government of Guam Activates Cyber Incident Response; Global Vulnerability Under Investigation

The Government of Guam activated its cyber incident response after identifying a widespread incident linked to a critical vulnerability affecting cPanel-hosted websites. Officials said response teams were investigating and securing affected government systems while essential and emergency operations remained available.

Bureau of Statistics and Plans Updates Public Comment Procedures

The Bureau of Statistics and Plans said its website was experiencing service disruption because of the widespread cPanel cyber incident. It directed residents to Google Drive, email, and in-person alternatives so public-comment access and submissions could continue.

CVE-2026-41940: Response, Actions and Next Steps

cPanel identified CVE-2026-41940 as a critical authentication vulnerability in the cPanel & WHM session-management layer. A specially crafted request could cause an unauthenticated session to be treated as authenticated and grant access without valid credentials. Updates were released April 28, and CISA added the flaw to its Known Exploited Vulnerabilities catalog May 1.

Bureau of Statistics and Plans Website Restoration Update

BSP’s official restoration notice remained live August 10. It said downloads and embedded content were temporarily unavailable and that the agency was restoring the site and securely re-uploading files, data sets, reports and media after the cPanel compromise.

See something that needs correction?

Signed-in members can report an error, update, or missing source.