Mitchell County, North Carolina

Mitchell County detected ransomware on its network Oct. 20, 2025, after unauthorized access began four days earlier. County communications were disrupted, and investigators later determined that attackers stole personal and protected health information.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
DysruptionHub assesses with high confidence that Mitchell County, North Carolina, experienced a ransomware attack in October 2025. The county’s data security notice says it detected ransomware Oct. 20 and that an unauthorized party accessed its network from Oct. 16 through Oct. 20. Investigators found that the intruders took personal and protected health information.
The county reported phone and email outages in late October. Our reporting documented those county service alerts and the later ransomware disclosure. The public record does not establish that every county service or facility was affected, or that emergency response was interrupted.
The county says it securely restored its network. It completed a review of affected data April 1, 2026, and began mailing notices May 1. The notice does not give a precise date for restoration of phone or email service, and the record does not establish whether a ransom was demanded or paid.
The county first described the late-October outages as technical issues. Its Dec. 19 notice identified ransomware. The later May 2026 notice documented the access window, theft and completed data review.
The county’s direct account supports high confidence in the ransomware and data theft. The available notices do not establish the initial access method, malware family, number of systems encrypted, ransom demand or actor identity. A negative search for a named leak-site claim is not proof that none exists.
The exact duration of the communications outages, full service impact, restoration date, final number of affected people and any extortion activity remain unresolved.

Administrative-office place anchor; no facility-specific damage claimed.
We reported that county phone and email outages in late October preceded its Dec. 19 ransomware disclosure and that Department of Social Services health information was taken.
Mitchell County said it detected ransomware Oct. 20, 2025, found unauthorized access from Oct. 16-20 and confirmed theft of personal and protected health information. It said its network was securely restored before data review and May 2026 notices.
Signed-in members can report an error, update, or missing source.