Murray County Government

Murray County, Georgia closed or limited several government offices after a ransomware attack disrupted county computer systems on May 13, 2026. County officials later said most systems had been restored and that the county paid $200,000 to prevent attackers from publishing county data, while 911, public safety, and voting remained available.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Unauthorized access to systems, accounts, networks, or data.
Threats to publish or sell stolen data without evidence of encryption.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
A primary service, system, platform, or operational capability became entirely unavailable.
Internal or external network connectivity was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.
The actor explicitly threatened to publish or publicly release victim data or incident details.
A source reported that the victim, insurer, intermediary, or another party made a ransom or extortion payment.
Murray County’s May 13 public notice said the tax commissioner, tax assessor, probate and juvenile-court offices would remain closed until the county network was restored, while other offices operated with limitations and voting continued. DysruptionHub’s published report documented that the county described the disruption as a cyberattack and said 911 and public-safety operations remained available.
Subsequent WTVC reporting said county officials identified the incident as ransomware, restored most systems, and paid $200,000 to prevent publication of county data. DysruptionHub assesses with high confidence that this was a confirmed ransomware and data-extortion incident with material disruption to county administrative services. The available statements do not establish whether files or systems were encrypted.
The attack affected county functions that depend on networked records, applications and office communications. Residents encountered closed offices and could not complete some tax, tag, assessment, probate and court-related business through normal channels. The disruption therefore affected both staff workflows and public access to routine government services.
Critical public-safety and election functions were maintained. County statements said 911, public safety and voting continued, which limits the supported impact on emergency and election operations. The incident nevertheless produced a substantial administrative outage across several county offices.
Murray County publicly disclosed the operational disruption on May 13, identifying the offices that were closed or limited and tying their reopening to network restoration. Later county statements identified the event as ransomware and disclosed that most systems were operational and that the county paid the attackers after consulting outside cybersecurity and forensic advisers.
The county said the payment was intended to prevent publication of county data. That supports data-theft extortion and a public-disclosure threat, but the public record does not identify the data involved, establish whether the attacker provided samples, independently confirm exfiltration, or show that any information was ultimately released.
Confidence is high that ransomware occurred because county officials used that characterization and reported a payment to the attackers. Confidence is high that government services were disrupted because the county’s own notice documented closed and limited offices.
Confidence is medium that data was exfiltrated. The payment rationale indicates that attackers claimed possession of county data and threatened publication, but no forensic report, affected-data inventory, breach notice or independent validation was identified. The payment was described as preventing publication, not obtaining a decryptor, and no available statement confirms encryption. No threat actor was named.
By June 12, county officials said the ransomware attack had been resolved and most systems were operational while secure restoration continued. This provides positive recovery evidence, although the public record does not establish that every system and backlog had returned to normal. DysruptionHub therefore assesses the operational incident as resolved based on the county’s restoration statement.
The reviewed sources do not establish the initial access vector, compromised account or device, ransomware family, whether encryption occurred, dwell time, backup impact, affected servers or exact restoration sequence. They also do not identify the data categories allegedly stolen, the number of affected individuals or records, the payment method, whether any data was published, or the identity of the attackers.

The Census Bureau estimated Murray County’s population at 41,607 on July 1, 2025, an increase of 4.1 percent from the April 2020 estimates base.
The Census Bureau estimated Chatsworth’s population at 5,029 on July 1, 2025, an increase of 2.9 percent from the April 2020 estimates base.
The joint plan describes Chatsworth and Eton in the Appalachian Great Valley, the Cohutta Mountains and Fort Mountain to the east, and a local industrial base strongly associated with carpet and floor-covering manufacturing.
Murray County said the tax commissioner, tax assessor, probate and juvenile-court offices would remain closed until network restoration. It said other offices would operate with limitations and voting would continue as scheduled.
Murray County said a cyberattack closed or limited tax, assessor, probate, juvenile-court, and other county offices while 911, public safety, and primary voting remained available.
WTVC reported that four Murray County offices were closed while the county dealt with a cyberattack, leaving residents unable to complete some tax and tag business through normal channels.
WTVC reported that Murray County identified the incident as ransomware, restored most computers, and paid $200,000 after consulting cybersecurity and forensic advisers to prevent attackers from publishing county data.
Government Technology reported that Murray County paid $200,000 following the ransomware attack first revealed May 13, that most computers had been restored, and that the county was strengthening security measures.
Signed-in members can report an error, update, or missing source.