Skip to content

Mitchell County ransomware attack

Summary

Mitchell County, North Carolina logo

Mitchell County detected ransomware on its network Oct. 20, 2025, after unauthorized access began four days earlier. County communications were disrupted, and investigators later determined that attackers stole personal and protected health information.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

Operational impacts

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Mitchell County, North Carolina, experienced a ransomware attack in October 2025. The county’s data security notice says it detected ransomware Oct. 20 and that an unauthorized party accessed its network from Oct. 16 through Oct. 20. Investigators found that the intruders took personal and protected health information.

Operational significance

The county reported phone and email outages in late October. Our reporting documented those county service alerts and the later ransomware disclosure. The public record does not establish that every county service or facility was affected, or that emergency response was interrupted.

Current status

The county says it securely restored its network. It completed a review of affected data April 1, 2026, and began mailing notices May 1. The notice does not give a precise date for restoration of phone or email service, and the record does not establish whether a ransom was demanded or paid.

Disclosure posture

The county first described the late-October outages as technical issues. Its Dec. 19 notice identified ransomware. The later May 2026 notice documented the access window, theft and completed data review.

Confidence and uncertainty

The county’s direct account supports high confidence in the ransomware and data theft. The available notices do not establish the initial access method, malware family, number of systems encrypted, ransom demand or actor identity. A negative search for a named leak-site claim is not proof that none exists.

Analytic gaps

The exact duration of the communications outages, full service impact, restoration date, final number of affected people and any extortion activity remain unresolved.

Organizations involved

Impacted locations

Sources

Notice of Data Security Incident

Mitchell County said it detected ransomware Oct. 20, 2025, found unauthorized access from Oct. 16-20 and confirmed theft of personal and protected health information. It said its network was securely restored before data review and May 2026 notices.

See something that needs correction?

Signed-in members can report an error, update, or missing source.