Skip to content

Greene County cyber incident disrupts government services

Summary

Greene County, Georgia logo

Greene County, Georgia, took its government network offline after identifying a cybersecurity incident July 9, 2026, disrupting payments and public-request processing while 911 and sheriff operations continued. By August 3, the county had removed its incident notice and the tax-payment application had returned to its normal verification gateway, with no later impact report found; operations are presumed resolved, while final forensic findings remain unpublished.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Payment processing disruption

    The organization could not process, receive, issue, reconcile, or record payments normally.

  • Transaction processing disruption

    Business, financial, customer, administrative, or operational transactions could not be completed normally.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Backlog created

    The disruption caused an accumulation of unprocessed requests, cases, orders, records, appointments, or other work.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Greene County, Georgia, experienced a cybersecurity incident affecting its government network beginning July 9, 2026. The county’s July 15 notice said its contracted technology provider took county servers offline to contain the incident and limit potential damage. Cybersecurity specialists were rebuilding systems, and law enforcement had been notified.

The public record confirms a cyber incident and broad network shutdown but does not establish the intrusion method or directly affected system set. Officials have not identified an initial-access vector, compromised account, exploited vulnerability, malware family, encryption activity, persistence mechanism or responsible actor. Rebuilding systems is consistent with a cautious containment and recovery process but does not by itself establish ransomware or destructive activity.

Operational significance

DysruptionHub’s published report documented a complete county network outage affecting the courthouse, commissioners’ offices, tax commissioner, tax assessor, building and zoning, elections, public works, recreation, public-safety administration and senior center. Offices could not accept payments or process some public requests, and the property-tax system was unavailable for in-person payment processing.

The disruption affected resident-facing government administration as well as internal operations. Transaction and records processing stopped or slowed across multiple offices, staff could not work normally, public access was restricted and unresolved work likely accumulated. The contracted online tax-payment portal still displayed an unavailability notice July 26, confirming at least 17 days of public-facing payment disruption.

Emergency operations were partly insulated. The county said 911 communications and the Greene County Sheriff’s Office were not affected and remained fully operational. The reviewed evidence does not establish interruption to emergency dispatch or core sheriff operations, although public-safety administration was included in the broader county outage notice.

Recovery and current status

Operations are presumed resolved. By August 3, Greene County had removed the July 15 incident notice, its current online-payments and Tax Commissioner websites advertised online property-tax payment, and the Government Window payment application reached its normal anti-bot verification gateway rather than the July 26 unavailability notice. No later county notice or credible report documented continuing payment outages, office disruption, workarounds or restoration activity.

These are credible recovery signals, but they do not establish a confirmed closure date. The county has not issued a retrospective all-clear or explicitly said that every affected system and office returned to normal. The payment application’s public landing page was available, but the available evidence does not establish that the full transaction workflow had been restored. July 26 therefore remains the latest confirmed date of operational impact, not a known restoration date.

Disclosure posture

Greene County directly acknowledged the cybersecurity incident, network shutdown, contracted technology provider’s role and system rebuild. Its July 15 notice said investigators had found no evidence that information was accessed or exfiltrated. The notice was no longer publicly available August 3.

The no-access/no-exfiltration statement is an important official finding but not a final technical determination. The county has not published the forensic basis, identified reviewed systems or said that the investigation is complete. As of August 3, no later breach notice, regulator filing, affected-data category or affected-person count had been found.

Confidence and uncertainty

Confidence is high that malicious or unauthorized cyber activity triggered the county’s response because Greene County directly characterized the event as a cybersecurity incident. Confidence is high that the response caused material government-service disruption because county and public notices identified affected offices and unavailable functions, and the tax-payment portal continued to display an unavailability notice July 26.

The incident caused a data-availability impact because authorized staff and residents could not use the property-tax system and payment application. Confidentiality and integrity impacts remain unresolved: the county reported no evidence of accessed or exfiltrated information, but it has not issued a final investigative conclusion. Ransomware involvement and threat-actor attribution remain unresolved, while targeted research found no known extortion indicator.

Analytic gaps

The public record does not establish when unauthorized activity began, how the incident was detected, which servers or applications were directly affected, whether credentials were compromised, or whether files were encrypted, altered or destroyed. It also does not identify the contracted technology provider, incident-response specialists, investigating law-enforcement agencies or recovery method.

The precise restoration date, any residual backlog and the final confidentiality and integrity findings remain unknown. A later forensic report, breach notice, actor claim or retrospective restoration statement could materially change the assessment.

Organizations involved

Impacted locations

Sources

Greene County, Georgia, cybersecurity incident disrupts county services

DysruptionHub reported that Greene County took its network offline after discovering a July 9 cybersecurity incident, disrupting payments and request processing across tax, court, administrative, elections, public works, recreation, and other offices while 911 and the sheriff remained operational.

Why Greene County took its entire computer network offline

FOX 5 Atlanta reported that Greene County identified a cybersecurity incident on July 9, contractors disconnected servers to contain it, and emergency 911 dispatch and the sheriff’s department remained fully operational.

Cyber Incident Being Investigated

Greene County said it identified a cybersecurity incident July 9, took county servers offline through its contracted technology provider, notified law enforcement and was rebuilding systems. It reported no evidence of accessed or exfiltrated information and said 911 communications and the sheriff’s office remained operational. By August 3, the notice URL redirected to a county 404 page and was no longer listed publicly.

Greene County GA - Tax Payments

The Greene County Tax Commissioner’s contracted payment page displayed an online-tax-payment unavailability notice July 26. On August 3, the tax application instead reached its normal anti-bot verification gateway; CAPTCHA verification prevented testing the post-verification transaction flow.

Greene County Tax Commissioner

The Greene County Tax Commissioner’s live website said residents could securely pay property taxes online and linked to the Government Window tax application on August 3, supporting an inference that the earlier payment outage had ended.

Greene County, Georgia official website

The official county website identifies Greene County government and its offices at 1034 Silver Drive in Greensboro, Georgia, and displayed the cybersecurity incident notice while the main website remained online.

See something that needs correction?

Signed-in members can report an error, update, or missing source.