Skip to content

Jackson County Sheriff's Office ransomware incident

Summary

Jackson County Sheriff's Office logo

Ransomware disabled the Jackson County Sheriff’s Office network in Indiana in March 2026, leaving computers, Wi-Fi and the police-report system inaccessible. Dispatchers shifted to Seymour Police Department computers, officers wrote reports in Word documents and technicians rebuilt the environment while officials said the county would not pay a ransom.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Phishing

    The use of deceptive messages or websites to trick people into revealing information, transferring funds or executing malicious content.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

Extortion indicators

  • Payment denied

    An authoritative source stated that no ransom or extortion payment was made.

Incident narrative

Analyst assessment

The Jackson County Sheriff’s Office in Indiana experienced a confirmed ransomware incident that disabled its network in March 2026. The Indiana Daily Student quoted Lt. Adam Nicholson saying ransomware affected the office’s entire network and caused corruption severe enough to require wiped computers, replacement hardware and a new infrastructure build. His account is direct affected-organization evidence even though the sheriff’s office did not publish a separate online notice.

The available evidence supports ransomware, but it does not identify the malware family, show a ransom note or disclose the amount or terms of a demand. Nicholson said the county would not pay.

Operational significance

The incident made office computers, Wi-Fi and the police-report filing system inaccessible. Dispatchers used computers at the Seymour Police Department, while officers prepared reports in Microsoft Word because the normal filing system was unavailable. Those workarounds allowed law-enforcement activity to continue outside its normal environment.

Nicholson also said it was unclear how much material could be recovered from external hard drives and identified sex-offender-registry files among the records of concern. That establishes loss of normal access and uncertain recoverability, not confirmed theft or publication.

Current status

The latest dated operational account said the network remained shut down March 25 while technicians rebuilt systems. Nicholson hoped to restore report filing the following week, but no authoritative all-clear or final restoration date was found.

Because more than 30 days have passed since the latest documented impact and no newer evidence shows continuing disruption, the incident is presumed resolved. That assessment does not claim that every record was recovered.

Confidence and uncertainty

Confidence is high that ransomware caused the disruption and that the network, computers, Wi-Fi and filing system were unavailable. Confidence is medium that a malicious email was the initial access vector because Nicholson attributed that explanation to technical support and no public forensic report independently confirms it.

No stable threat-actor claim was identified using the sheriff’s canonical name and jacksoncountysheriffin.org. Attribution and data theft remain unresolved.

Analytic gaps

Public sources do not establish the exact initial-access or activation date, malicious message or account, ransomware family, encryption scope, affected backups, ransom amount, restoration completion date or whether law-enforcement records were ultimately recovered, viewed or copied.

Organizations involved

Impacted locations

Sources

Jackson County sheriff's office hit by ransomware in Indiana

Ransomware knocked the Jackson County Sheriff’s Office network offline, forced dispatchers to use Seymour Police Department computers and left officers writing reports in Word documents while systems were rebuilt.

Ransomware attack crashes Jackson County Sheriff's Office computer systems

Lt. Adam Nicholson said ransomware affected the sheriff’s entire network, leaving the report system, Wi-Fi and computers inaccessible while dispatchers moved to Seymour police computers and technicians wiped or replaced equipment.

Gazetteer Files

The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.

Jackson County Sheriff's Office official website

The organization’s official website describes its identity, services, operating role and public or customer-facing programs.

See something that needs correction?

Signed-in members can report an error, update, or missing source.