Plymouth County Sheriff's Department

Plymouth County Correctional Facility shut down its computer system after detecting unauthorized server access on August 13, suspending in-person visits because staff could not retrieve visitor-clearance records. Attorney visits and incarcerated people’s tablet and phone access continued, while state police, the FBI and the Department of Homeland Security investigated. The public record does not establish ransomware, extortion, a threat actor or whether information was acquired.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Unauthorized access to systems, accounts, networks, or data.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
A primary service, system, platform, or operational capability became entirely unavailable.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
Police, fire, emergency medical, corrections, emergency management, or other public-safety operations were materially affected.
Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
We reported that an intruder accessed servers at the Plymouth County Correctional Facility on Aug. 13, 2026, prompting officials to shut down its computer system and suspend in-person visits. Department spokesperson Karen Barry told the Plymouth Independent that information technology employees detected the intrusion. Massachusetts State Police, the FBI and the Department of Homeland Security were investigating.
The department’s account supports a confirmed cyber assessment and unauthorized-access mechanism. It does not establish ransomware, extortion or a threat actor. Barry said it was unclear what information, if any, the intruder accessed. The department said it had no evidence that personal information was misused, but that statement does not determine whether information was viewed or acquired.
The shutdown prevented staff from retrieving security records used to clear visitors, so the facility suspended in-person visits. Attorney visits continued, and incarcerated people retained access to telephones and tablets. The department said the incident did not threaten the facility’s physical security or the safety of staff, incarcerated people or the public.
The incident is presumed resolved under the registry’s operational-status policy. Aug. 15 remains the latest documented impact date: the computer system was inaccessible and in-person visits were suspended. No newer dated operational-impact, resumed-visitation or restoration notice was found through the Sept. 20 research cutoff. Thirty-six days without a newer impact observation requires presumed resolved; this is an aging inference, not evidence that officials issued an all-clear.
Confidence is high that unauthorized server access caused the computer shutdown and visitor restrictions because the account relies on direct statements from the affected organization. Data impact remains unresolved: the absence of evidence that personal information was misused is not evidence that information was not accessed or acquired. Ransomware, extortion and actor attribution also remain unestablished.
The public record does not establish whether information was viewed, acquired, altered or destroyed; the initial access vector; the specific affected systems; ransomware or an extortion demand; the intruder’s identity; or the dates of full system restoration and resumed in-person visits.

We reported that unauthorized server access prompted a computer shutdown and suspension of in-person visits at Plymouth County Correctional Facility. No restoration date, ransomware, extortion or actor had been disclosed.
A Sheriff’s Department spokesperson said an intruder bypassed the jail’s security system and accessed servers, prompting an immediate computer shutdown and suspension of in-person visits because clearance records were unavailable.
The department identifies the Plymouth County Correctional Facility at 26 Long Pond Road in Plymouth, Massachusetts, and publishes its inmate-visitation information on this page.
The organization’s official website describes its identity, services, operating role and public or customer-facing programs.
Signed-in members can report an error, update, or missing source.