Skip to content

Plymouth County jail computer shutdown after unauthorized server access

Summary

Plymouth County Sheriff's Department logo

Plymouth County Correctional Facility shut down its computer system after detecting unauthorized server access on August 13, suspending in-person visits because staff could not retrieve visitor-clearance records. Attorney visits and incarcerated people’s tablet and phone access continued, while state police, the FBI and the Department of Homeland Security investigated. The public record does not establish ransomware, extortion, a threat actor or whether information was acquired.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

We reported that an intruder accessed servers at the Plymouth County Correctional Facility on Aug. 13, 2026, prompting officials to shut down its computer system and suspend in-person visits. Department spokesperson Karen Barry told the Plymouth Independent that information technology employees detected the intrusion. Massachusetts State Police, the FBI and the Department of Homeland Security were investigating.

The department’s account supports a confirmed cyber assessment and unauthorized-access mechanism. It does not establish ransomware, extortion or a threat actor. Barry said it was unclear what information, if any, the intruder accessed. The department said it had no evidence that personal information was misused, but that statement does not determine whether information was viewed or acquired.

Operational significance

The shutdown prevented staff from retrieving security records used to clear visitors, so the facility suspended in-person visits. Attorney visits continued, and incarcerated people retained access to telephones and tablets. The department said the incident did not threaten the facility’s physical security or the safety of staff, incarcerated people or the public.

Current status

The incident is presumed resolved under the registry’s operational-status policy. Aug. 15 remains the latest documented impact date: the computer system was inaccessible and in-person visits were suspended. No newer dated operational-impact, resumed-visitation or restoration notice was found through the Sept. 20 research cutoff. Thirty-six days without a newer impact observation requires presumed resolved; this is an aging inference, not evidence that officials issued an all-clear.

Confidence and uncertainty

Confidence is high that unauthorized server access caused the computer shutdown and visitor restrictions because the account relies on direct statements from the affected organization. Data impact remains unresolved: the absence of evidence that personal information was misused is not evidence that information was not accessed or acquired. Ransomware, extortion and actor attribution also remain unestablished.

Analytic gaps

The public record does not establish whether information was viewed, acquired, altered or destroyed; the initial access vector; the specific affected systems; ransomware or an extortion demand; the intruder’s identity; or the dates of full system restoration and resumed in-person visits.

Organizations involved

Impacted locations

Sources

Server intrusion shuts down Plymouth County jail computers in Massachusetts

We reported that unauthorized server access prompted a computer shutdown and suspension of in-person visits at Plymouth County Correctional Facility. No restoration date, ransomware, extortion or actor had been disclosed.

Jail visits suspended after cyber attack

A Sheriff’s Department spokesperson said an intruder bypassed the jail’s security system and accessed servers, prompting an immediate computer shutdown and suspension of in-person visits because clearance records were unavailable.

Visits

The department identifies the Plymouth County Correctional Facility at 26 Long Pond Road in Plymouth, Massachusetts, and publishes its inmate-visitation information on this page.

Plymouth County Sheriff's Department official website

The organization’s official website describes its identity, services, operating role and public or customer-facing programs.

See something that needs correction?

Signed-in members can report an error, update, or missing source.