Analyst assessment
Harrison County initially described disruptions to county network systems as a cybersecurity incident. The county later stated in its Notice of Cyber Incident that it quickly determined the event was ransomware, engaged outside cybersecurity specialists and coordinated with the FBI, CISA and the West Virginia Intelligence Fusion Center. Our April 25 report documented the first public service effects and the county’s early response. Separately, DysruptionHub assesses with high confidence that ransomware caused a material disruption to county-government operations.
The public record does not establish the initial access vector, exploited vulnerability, compromised account or device, malware family beyond the county’s ransomware characterization, or the scope of encryption. The county said personal information may have been accessed or acquired because of the nature of the incident, but it did not confirm that outcome and reported no evidence of data misuse.
Operational significance
The disruption affected services at the Harrison County Courthouse and Sheriff’s Tax Office. Residents were advised to call before visiting county offices, and local reporting documented people being turned away when attempting to pay property taxes. County personnel and outside experts restored systems in stages, while some administrative reporting functions within the Sheriff’s Office remained affected into May.
A May 6 county update reported by WV News said more computers were online but not all systems had been fully restored. County officials said core public-safety systems and 911 were never at risk and that the independent election environment was unaffected. Those boundaries support a partial county-service disruption rather than a complete shutdown of county government.
Disclosure posture
The county’s first public statements confirmed a cybersecurity incident and operational effects while officials said the investigation was in its early stages. The later notice refined that account by confirming ransomware, identifying potentially implicated personal-information categories and stating that operations had returned to normal. The categories could include names, addresses, dates of birth, driver’s-license or state-identification numbers and Social Security numbers, but the notice did not say that every category or every resident was affected.
On May 18, SafePay claimed responsibility on its data-leak site and reportedly imposed a three-day payment deadline for data it said it had stolen. Comparitech said the county had not acknowledged the SafePay claim and that the reporting organization could not independently verify it. The claim therefore supports a low-confidence attribution and documented extortion indicators, not confirmed SafePay responsibility or confirmed data theft.
Current status
The county’s current notice says its systems are secure and operations have returned to normal. That authoritative restoration statement supports resolved operational status, although the public record does not establish the exact date every affected system and administrative function was restored.
Confidence and uncertainty
Confidence is high that ransomware occurred and disrupted county operations because the affected county confirmed both findings and multiple local reports documented the service effects and staged restoration. Confidence is high that core public-safety and election systems remained available based on county statements.
Data impact remains unresolved: the county described access or acquisition as possible and offered identity monitoring, while SafePay claimed theft, but neither source establishes the number of affected people, confirmed acquisition, publication or misuse. SafePay attribution remains low confidence because the public claim is unverified and unacknowledged by the county. The available record does not establish whether the county received a direct ransom note, negotiated or made any payment.
Analytic gaps
The public record does not identify the initial access vector, compromised account or host, exploited vulnerability, ransomware variant, dwell time, persistence, encryption scope, affected-system inventory, exfiltration evidence, confirmed data categories, affected-person count, sample publication, ransom amount, direct victim contact, negotiation or payment activity. It also does not provide a detailed restoration timeline, forensic report, final attribution or exact date on which every system returned to normal.