Skip to content

ImageMaster MuniOS ransomware attack

Summary

ImageMaster LLC logo

A cyberattack encrypted ImageMaster server drives and took its MuniOS municipal bond document platform offline for several days in October 2025. Issuers used the MSRB EMMA system to post preliminary official statements. ImageMaster said the site returned Oct. 16 and attackers did not obtain data.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted location

Critical infrastructure sector

Incident characteristics

Assessments

Operational impacts

Incident narrative

Analyst assessment

DysruptionHub reported the MuniOS outage Oct. 15, 2025, following Bloomberg reporting that described ransomware. ImageMaster manager Albert Rodriguez later told Bloomberg and The Bond Buyer that attackers exploited a firewall vulnerability, encrypted server drives and caused the company servers to fail. His account supports a confirmed ransomware-style encryption event, although the public material does not identify a named group, ransom demand or payment.

Operational significance

MuniOS, ImageMaster’s platform for municipal bond offering documents, was unavailable for several days. The Municipal Securities Rulemaking Board’s Oct. 14 notice explained how issuers could post preliminary official statements on EMMA instead; it did not itself name MuniOS. Investors and issuers lost access to the usual MuniOS distribution channel and had to use alternatives. The company’s headquarters is in Ann Arbor, Michigan; no evidence shows a physical facility outage or that every municipality served by the site suffered an operational disruption.

Restoration and data scope

Bloomberg and The Bond Buyer reported that MuniOS returned Oct. 16 after ImageMaster rebuilt servers. Rodriguez said attackers did not obtain data. That is the company’s assessment in the reviewed reporting; no public forensic report was located. The exact intrusion start, named actor and financial consequences remain unknown. A separate Akira leak-site listing for ImageMaster appeared in April 2026 and is not evidence that Akira caused this October 2025 event.

Organizations involved

Impacted location

Sources

Cyber Attack Ensnares $4.3 Trillion Muni Market’s Key Site

Bloomberg reported the ImageMaster-operated MuniOS site had been unavailable for several days after a ransomware attack.

Key Muni Market Website MuniOS Is Back Online After Outage

MuniOS returned Oct. 16; Rodriguez said attackers exploited a firewall weakness, encrypted server drives and caused server failures, but did not obtain data.

MuniOS Is Back Online After Cyberattack

Rodriguez said attackers encrypted server drives through a firewall vulnerability; servers were rebuilt, MuniOS returned, and he said no data was taken.

See something that needs correction?

Signed-in members can report an error, update, or missing source.