Peak Software Systems, Inc.

Attackers encrypted Peak Software Systems infrastructure, backups and internal systems supporting the Sportsman platform, disrupting municipal recreation registration, reservations, rentals and payments in at least six cities. Lehi City later said an unauthorized party accessed systems and that certain Legacy Center files may have been accessed or acquired. Services were restored, the incident was contained and no stable threat-actor claim was found.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Unauthorized access to systems, accounts, networks, or data.
Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Backup data or backup systems were accessed, encrypted, deleted, altered, disabled, or otherwise compromised.
A primary service, system, platform, or operational capability became entirely unavailable.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
A specific application or software platform became unavailable or unusable.
The organization could not process, receive, issue, reconcile, or record payments normally.
Business, financial, customer, administrative, or operational transactions could not be completed normally.
Appointment, booking, reservation, dispatch, staffing, or other scheduling functions were unavailable or impaired.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.
The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
We reported that attackers encrypted Peak Software Systems infrastructure, backups and internal systems supporting the Sportsman platform, disrupting municipal parks and recreation services. Clute said Peak obtained decryption keys and began restoration March 1. Lehi City later said an unauthorized party accessed certain systems and that files held in Sportsman may have been accessed or acquired.
The evidence confirms a cyber incident and supports a high-confidence ransomware assessment. Encryption, affected backups and the use of decryption keys form a strong ransomware pattern, but the public record does not identify a ransomware family, ransom demand or stable threat-actor claim.
Municipal customers lost online and in-person registration, reservations and rentals. Some facilities shifted to cash, and program deadlines or swim-lesson registration were delayed. Documented downstream organizations are the municipal governments of Clute, Texas; Garden City, Michigan; Brigham City, South Jordan and Lehi, Utah; and Monroe, Wisconsin.
Brigham City said its delayed swim registration would open March 16. Lehi’s April 9 notice says systems had been restored and the incident contained. Because that notice describes the February event retrospectively rather than a continuing April outage, March 16 remains the last documented operational impact date and the incident is resolved.
Confidence is high that the attack encrypted Peak systems and disrupted Sportsman services. Lehi’s notice supports possible confidentiality impact involving names, dates of birth, contact details, emergency contacts, school information, parents’ names and home addresses, but it does not establish that those files were accessed or acquired. Lehi said Peak had no current indication that Social Security numbers or financial account information were involved; Clute said payment cards were processed in a separate environment.
Garden City publicly documented a service disruption Feb. 26 without cyber wording. An official Clute cyber notice was available before and underpinned our March 5 report, making this an organization-first cyber disclosure followed by external reporting. Feb. 26 remains the incident’s first public operational signal, while March 5 is the earliest dated public cyber-specific signal established in the record.
The public record does not establish the actor, initial-access vector, ransomware family, ransom demand, payment, verified data acquisition or exfiltration, complete affected-customer count or the exact date of Clute’s first cyber post.

The Lehi Legacy Center's Sportsman services were disrupted and its uploaded patron files were included in the city's breach notice.
We reported that attackers encrypted Peak Software Systems infrastructure, backups and internal systems, disrupting Sportsman registration, rentals and payments across several municipalities.
Brigham City said software problems delayed swim-lesson registration and that registration would open March 16.
Lehi said an unauthorized party accessed systems and disrupted Sportsman on Feb. 26. Certain Legacy Center files may have been accessed or acquired; systems were restored and the incident contained.
Peak says it is headquartered in Sandy, Utah, develops Sportsman software for recreation organizations and serves more than 500 clients worldwide.
The official Clute Parks and Recreation portal offers activity registration and membership renewal, links to clutetexas.gov and identifies Sportsman Cloud as its platform.
Garden City’s official page directs 2026 online registrations to its Sportsman portal and in-person registrations to the Radcliff Center.
The City of Monroe Parks, Recreation and Forestry page identifies the municipal department and its online ActivityReg registration service.
South Jordan’s official portal describes its activity-registration and amenity-reservation service, links to sjc.utah.gov and identifies Sportsman Cloud as its platform.
The organization’s official website describes its identity, services, operating role and public or customer-facing programs.
The organization’s official website describes its identity, services, operating role and public or customer-facing programs.
The organization’s official website describes its identity, services, operating role and public or customer-facing programs.
The organization’s official website describes its identity, services, operating role and public or customer-facing programs.
The organization’s official website describes its identity, services, operating role and public or customer-facing programs.
The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.
The organization’s official website describes its identity, services, operating role and public or customer-facing programs.
Signed-in members can report an error, update, or missing source.