Skip to content

Murray County ransomware closes government offices

Summary

Murray County Government logo

Murray County, Georgia closed or limited several government offices after a ransomware attack disrupted county computer systems on May 13, 2026. County officials later said most systems had been restored and that the county paid $200,000 to prevent attackers from publishing county data, while 911, public safety, and voting remained available.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

  • Data extortion

    Threats to publish or sell stolen data without evidence of encryption.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Facility closure

    One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Payment reported

    A source reported that the victim, insurer, intermediary, or another party made a ransom or extortion payment.

Incident narrative

Analyst assessment

Murray County’s May 13 public notice said the tax commissioner, tax assessor, probate and juvenile-court offices would remain closed until the county network was restored, while other offices operated with limitations and voting continued. DysruptionHub’s published report documented that the county described the disruption as a cyberattack and said 911 and public-safety operations remained available.

Subsequent WTVC reporting said county officials identified the incident as ransomware, restored most systems, and paid $200,000 to prevent publication of county data. DysruptionHub assesses with high confidence that this was a confirmed ransomware and data-extortion incident with material disruption to county administrative services. The available statements do not establish whether files or systems were encrypted.

Operational significance

The attack affected county functions that depend on networked records, applications and office communications. Residents encountered closed offices and could not complete some tax, tag, assessment, probate and court-related business through normal channels. The disruption therefore affected both staff workflows and public access to routine government services.

Critical public-safety and election functions were maintained. County statements said 911, public safety and voting continued, which limits the supported impact on emergency and election operations. The incident nevertheless produced a substantial administrative outage across several county offices.

Disclosure posture

Murray County publicly disclosed the operational disruption on May 13, identifying the offices that were closed or limited and tying their reopening to network restoration. Later county statements identified the event as ransomware and disclosed that most systems were operational and that the county paid the attackers after consulting outside cybersecurity and forensic advisers.

The county said the payment was intended to prevent publication of county data. That supports data-theft extortion and a public-disclosure threat, but the public record does not identify the data involved, establish whether the attacker provided samples, independently confirm exfiltration, or show that any information was ultimately released.

Confidence and uncertainty

Confidence is high that ransomware occurred because county officials used that characterization and reported a payment to the attackers. Confidence is high that government services were disrupted because the county’s own notice documented closed and limited offices.

Confidence is medium that data was exfiltrated. The payment rationale indicates that attackers claimed possession of county data and threatened publication, but no forensic report, affected-data inventory, breach notice or independent validation was identified. The payment was described as preventing publication, not obtaining a decryptor, and no available statement confirms encryption. No threat actor was named.

Retrospective note

By June 12, county officials said the ransomware attack had been resolved and most systems were operational while secure restoration continued. This provides positive recovery evidence, although the public record does not establish that every system and backlog had returned to normal. DysruptionHub therefore assesses the operational incident as resolved based on the county’s restoration statement.

Analytic gaps

The reviewed sources do not establish the initial access vector, compromised account or device, ransomware family, whether encryption occurred, dwell time, backup impact, affected servers or exact restoration sequence. They also do not identify the data categories allegedly stolen, the number of affected individuals or records, the payment method, whether any data was published, or the identity of the attackers.

Organizations involved

Impacted locations

Sources

QuickFacts: Murray County, Georgia

The Census Bureau estimated Murray County’s population at 41,607 on July 1, 2025, an increase of 4.1 percent from the April 2020 estimates base.

QuickFacts: Chatsworth city, Georgia

The Census Bureau estimated Chatsworth’s population at 5,029 on July 1, 2025, an increase of 2.9 percent from the April 2020 estimates base.

Murray County Joint Comprehensive Plan

The joint plan describes Chatsworth and Eton in the Appalachian Great Valley, the Cohutta Mountains and Fort Mountain to the east, and a local industrial base strongly associated with carpet and floor-covering manufacturing.

County office closures during network restoration

Murray County said the tax commissioner, tax assessor, probate and juvenile-court offices would remain closed until network restoration. It said other offices would operate with limitations and voting would continue as scheduled.

Murray County, Georgia cyberattack closes county offices

Murray County said a cyberattack closed or limited tax, assessor, probate, juvenile-court, and other county offices while 911, public safety, and primary voting remained available.

Cyberattack closes some Murray County offices

WTVC reported that four Murray County offices were closed while the county dealt with a cyberattack, leaving residents unable to complete some tax and tag business through normal channels.

Murray County restores systems after ransomware attack, pays $200,000 fee

WTVC reported that Murray County identified the incident as ransomware, restored most computers, and paid $200,000 after consulting cybersecurity and forensic advisers to prevent attackers from publishing county data.

Murray County, Ga., Paid $200K After Ransomware Attack

Government Technology reported that Murray County paid $200,000 following the ransomware attack first revealed May 13, that most computers had been restored, and that the county was strengthening security measures.

See something that needs correction?

Signed-in members can report an error, update, or missing source.