Skip to content

Harrison County, West Virginia, ransomware attack

Summary

Harrison County Commission logo

Harrison County, West Virginia, discovered ransomware-related computer disruptions around April 23, 2026, affecting courthouse services, tax payments and administrative functions while public-safety and election systems remained intact. Operations later returned to normal, but the county warned that personal information may have been accessed; SafePay claimed responsibility and data theft, but the county did not confirm the claim or resulting exposure.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Payment processing disruption

    The organization could not process, receive, issue, reconcile, or record payments normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Countdown or payment deadline

    The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.

Incident narrative

Analyst assessment

Harrison County initially described disruptions to county network systems as a cybersecurity incident. The county later stated in its Notice of Cyber Incident that it quickly determined the event was ransomware, engaged outside cybersecurity specialists and coordinated with the FBI, CISA and the West Virginia Intelligence Fusion Center. Our April 25 report documented the first public service effects and the county’s early response. Separately, DysruptionHub assesses with high confidence that ransomware caused a material disruption to county-government operations.

The public record does not establish the initial access vector, exploited vulnerability, compromised account or device, malware family beyond the county’s ransomware characterization, or the scope of encryption. The county said personal information may have been accessed or acquired because of the nature of the incident, but it did not confirm that outcome and reported no evidence of data misuse.

Operational significance

The disruption affected services at the Harrison County Courthouse and Sheriff’s Tax Office. Residents were advised to call before visiting county offices, and local reporting documented people being turned away when attempting to pay property taxes. County personnel and outside experts restored systems in stages, while some administrative reporting functions within the Sheriff’s Office remained affected into May.

A May 6 county update reported by WV News said more computers were online but not all systems had been fully restored. County officials said core public-safety systems and 911 were never at risk and that the independent election environment was unaffected. Those boundaries support a partial county-service disruption rather than a complete shutdown of county government.

Disclosure posture

The county’s first public statements confirmed a cybersecurity incident and operational effects while officials said the investigation was in its early stages. The later notice refined that account by confirming ransomware, identifying potentially implicated personal-information categories and stating that operations had returned to normal. The categories could include names, addresses, dates of birth, driver’s-license or state-identification numbers and Social Security numbers, but the notice did not say that every category or every resident was affected.

On May 18, SafePay claimed responsibility on its data-leak site and reportedly imposed a three-day payment deadline for data it said it had stolen. Comparitech said the county had not acknowledged the SafePay claim and that the reporting organization could not independently verify it. The claim therefore supports a low-confidence attribution and documented extortion indicators, not confirmed SafePay responsibility or confirmed data theft.

Current status

The county’s current notice says its systems are secure and operations have returned to normal. That authoritative restoration statement supports resolved operational status, although the public record does not establish the exact date every affected system and administrative function was restored.

Confidence and uncertainty

Confidence is high that ransomware occurred and disrupted county operations because the affected county confirmed both findings and multiple local reports documented the service effects and staged restoration. Confidence is high that core public-safety and election systems remained available based on county statements.

Data impact remains unresolved: the county described access or acquisition as possible and offered identity monitoring, while SafePay claimed theft, but neither source establishes the number of affected people, confirmed acquisition, publication or misuse. SafePay attribution remains low confidence because the public claim is unverified and unacknowledged by the county. The available record does not establish whether the county received a direct ransom note, negotiated or made any payment.

Analytic gaps

The public record does not identify the initial access vector, compromised account or host, exploited vulnerability, ransomware variant, dwell time, persistence, encryption scope, affected-system inventory, exfiltration evidence, confirmed data categories, affected-person count, sample publication, ransom amount, direct victim contact, negotiation or payment activity. It also does not provide a detailed restoration timeline, forensic report, final attribution or exact date on which every system returned to normal.

Threat actor and claim

Listed as: Harrison County CommissionSource: otherPublished: Discovered:

Claim details

SafePay claimed responsibility for the April 2026 Harrison County Commission incident and reportedly imposed a three-day deadline for payment over data it said it stole. The county did not acknowledge the claim, and Comparitech said it could not independently verify attribution or theft.

Organizations involved

Impacted locations

Sources

Cybersecurity incident disrupts Harrison County, West Virginia, offices

DysruptionHub reported that a cybersecurity incident affected Harrison County network systems and prevented some courthouse and tax-office services. Officials engaged outside experts and law enforcement, and residents were advised to call ahead while the scope, ransomware involvement, data impact, actor and restoration timeline remained unresolved.

Harrison County public service announcement

Harrison County announced ongoing IT and network issues and advised residents to call before visiting the courthouse or General Services Building because some office services might be unavailable.

Harrison County Administrator: Good progress made to resolve cyberattack

WV News reported the county administrator’s update that more computers were online but not all systems were fully restored. Certain Sheriff’s Office administrative reporting functions remained affected, while core public-safety, 911 and independent election systems were not at risk or affected.

Cybercriminals say they hacked Harrison County, WV commission, demand ransom

Comparitech reported that SafePay claimed Harrison County Commission on May 18 and gave it three days to pay an undisclosed ransom for data the group said it stole. Comparitech said the county had not acknowledged the claim and the claim could not be independently verified.

Notice of Cyber Incident

The county said it discovered computer-system disruptions on or about April 23 and quickly determined it was a ransomware incident. It said systems were secure and operations had returned to normal, while warning that personal information might have been accessed or acquired and reporting no evidence of data misuse.

Harrison County Commission

Official profile information supporting the public description of Harrison County Commission.

Geographic profiles for selected U.S. locations

Official geographic reference used with local and state material to verify place names, jurisdiction types and location context for , harrison, clarksburg.

See something that needs correction?

Signed-in members can report an error, update, or missing source.