Skip to content

Passaic County ransomware incident

Summary

Passaic County logo

Passaic County said a March 4 ransomware event made its network, phones, computers and internet inoperable, and the county later said most operations had been restored. Medusa claimed responsibility and threatened to publish data, but the county did not confirm the attribution or the scope of any data access.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

Operational impacts

Extortion indicators

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Data sample published

    The actor published or shared a sample of allegedly stolen victim data to substantiate the extortion claim.

  • Countdown or payment deadline

    The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Passaic County experienced a confirmed ransomware incident beginning March 4, 2026. The county’s initial statement said malware affected its information technology systems and phone lines, and a later county resolution called the event ransomware and said the county network, including phones, computers and internet, became inoperable after suspicious activity was identified.

Medusa later claimed the county as a victim. Comparitech reported that the group demanded $800,000, threatened publication and posted images it described as stolen county documents. The claim is treated as evidence of extortion activity, not independent confirmation that Medusa caused the intrusion or that its data claims were authentic.

Operational significance

The loss of county phones, computers, internet and network access disrupted core communications and administrative technology used across county government. Our initial report documented that phone lines remained down into March 5 while county, state and federal officials investigated and contained the incident.

The public record does not establish that 911, dispatch, courts, public safety operations or particular resident services were interrupted. The county-wide service-area relationship reflects the affected government’s jurisdiction and does not mean every resident or facility experienced an outage.

Retrospective note

By March 18, the county said most operations had been restored while the investigation continued and investigators examined the nature and scope of unauthorized access to data. The county later authorized emergency contracts totaling up to $247,625 in response to the incident, and a July 14 meeting record documented additional response services.

Those records show an extended recovery effort but do not identify a final all-clear date for every system. No later reviewed source documented continuing operational disruption, so the material outage is presumed resolved rather than authoritatively closed.

Confidence and uncertainty

Confidence is high that the disruption and ransomware event occurred because Passaic County documented both the operational effects and the ransomware characterization in official records. Confidence is medium that unauthorized data access occurred because the county said investigators were determining its nature and scope, but the public record does not establish what data was viewed, copied or removed.

Threat-actor attribution remains low confidence. Medusa’s listing and demand are publicly reported and identify the county, but Passaic County did not attribute the incident to Medusa and the available sources do not independently validate the group’s evidence.

Analytic gaps

The public record does not establish the initial access vector, exploited vulnerability, compromised account or host, dwell time, ransomware variant, encryption scope, lateral movement, data categories, number of affected records, exfiltration scope, ransom payment status or complete restoration method.

The county also has not published a final investigative report or comprehensive restoration notice. Those gaps limit conclusions about the full technical scope and data consequences even though the ransomware incident and operational disruption are well documented.

Threat actor and claim

Listed as: Passaic CountySource: otherPublished: Discovered:

Claim details

Medusa claimed Passaic County, demanded $800,000 and threatened publication. The county did not confirm attribution, and the report did not independently verify responsibility or alleged data theft.

Organizations involved

Impacted locations

  • Paterson, New Jersey

    Medium Confidence

    Physical anchor for county government offices in Paterson; public evidence does not establish building-specific damage.

Sources

Passaic County, New Jersey malware attack knocks out phone lines

We reported that Passaic County’s malware attack disrupted information technology systems and left government phone lines down into March 5 while officials investigated and contained the incident.

Statement from Passaic County

Passaic County said a malware attack was affecting its information technology systems and phone lines and that county, state and federal officials were investigating and containing the incident.

Cybercriminals say they hacked Passaic County, NJ and demand ransom

Comparitech reported that Medusa listed Passaic County, demanded $800,000 and posted images it described as stolen documents. It also reported a March 18 county statement that most operations were restored while investigators examined unauthorized data access.

Resolution ratifying emergency contracts for the March 2026 ransomware event

The county resolution described a March 4 ransomware event in which the county network, including phone systems, computers and internet, became inoperable after suspicious activity was identified. It ratified emergency response contracts totaling up to $247,625.

Passaic County Board of County Commissioners meeting record for July 14, 2026

The July 14 meeting record shows the board adopted a resolution increasing an emergency contract for additional services needed in response to the county’s March 2026 ransomware event.

See something that needs correction?

Signed-in members can report an error, update, or missing source.