Claim details
Medusa claimed Passaic County, demanded $800,000 and threatened publication. The county did not confirm attribution, and the report did not independently verify responsibility or alleged data theft.
Passaic County said a March 4 ransomware event made its network, phones, computers and internet inoperable, and the county later said most operations had been restored. Medusa claimed responsibility and threatened to publish data, but the county did not confirm the attribution or the scope of any data access.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Unauthorized access to systems, accounts, networks, or data.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Internal or external network connectivity was unavailable or materially impaired.
The organization lost or materially restricted internet connectivity.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The actor explicitly threatened to publish or publicly release victim data or incident details.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
The actor published or shared a sample of allegedly stolen victim data to substantiate the extortion claim.
The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.
DysruptionHub assesses with high confidence that Passaic County experienced a confirmed ransomware incident beginning March 4, 2026. The county’s initial statement said malware affected its information technology systems and phone lines, and a later county resolution called the event ransomware and said the county network, including phones, computers and internet, became inoperable after suspicious activity was identified.
Medusa later claimed the county as a victim. Comparitech reported that the group demanded $800,000, threatened publication and posted images it described as stolen county documents. The claim is treated as evidence of extortion activity, not independent confirmation that Medusa caused the intrusion or that its data claims were authentic.
The loss of county phones, computers, internet and network access disrupted core communications and administrative technology used across county government. Our initial report documented that phone lines remained down into March 5 while county, state and federal officials investigated and contained the incident.
The public record does not establish that 911, dispatch, courts, public safety operations or particular resident services were interrupted. The county-wide service-area relationship reflects the affected government’s jurisdiction and does not mean every resident or facility experienced an outage.
By March 18, the county said most operations had been restored while the investigation continued and investigators examined the nature and scope of unauthorized access to data. The county later authorized emergency contracts totaling up to $247,625 in response to the incident, and a July 14 meeting record documented additional response services.
Those records show an extended recovery effort but do not identify a final all-clear date for every system. No later reviewed source documented continuing operational disruption, so the material outage is presumed resolved rather than authoritatively closed.
Confidence is high that the disruption and ransomware event occurred because Passaic County documented both the operational effects and the ransomware characterization in official records. Confidence is medium that unauthorized data access occurred because the county said investigators were determining its nature and scope, but the public record does not establish what data was viewed, copied or removed.
Threat-actor attribution remains low confidence. Medusa’s listing and demand are publicly reported and identify the county, but Passaic County did not attribute the incident to Medusa and the available sources do not independently validate the group’s evidence.
The public record does not establish the initial access vector, exploited vulnerability, compromised account or host, dwell time, ransomware variant, encryption scope, lateral movement, data categories, number of affected records, exfiltration scope, ransom payment status or complete restoration method.
The county also has not published a final investigative report or comprehensive restoration notice. Those gaps limit conclusions about the full technical scope and data consequences even though the ransomware incident and operational disruption are well documented.
Medusa claimed Passaic County, demanded $800,000 and threatened publication. The county did not confirm attribution, and the report did not independently verify responsibility or alleged data theft.

Models the affected county government's geographic remit; it does not assert that every resident or facility lost service.
Physical anchor for county government offices in Paterson; public evidence does not establish building-specific damage.
We reported that Passaic County’s malware attack disrupted information technology systems and left government phone lines down into March 5 while officials investigated and contained the incident.
Passaic County said a malware attack was affecting its information technology systems and phone lines and that county, state and federal officials were investigating and containing the incident.
Comparitech reported that Medusa listed Passaic County, demanded $800,000 and posted images it described as stolen documents. It also reported a March 18 county statement that most operations were restored while investigators examined unauthorized data access.
The county resolution described a March 4 ransomware event in which the county network, including phone systems, computers and internet, became inoperable after suspicious activity was identified. It ratified emergency response contracts totaling up to $247,625.
The July 14 meeting record shows the board adopted a resolution increasing an emergency contract for additional services needed in response to the county’s March 2026 ransomware event.
Signed-in members can report an error, update, or missing source.