Prince George County cyber incident disrupted services
Summary
Prince George County, Virginia, said a June 11, 2026 cyber incident disrupted phones, internet and online payments before systems were secured and normal operations resumed. The county said personal data may have been accessed and offered identity monitoring, while RansomHouse’s ransomware and attribution claims remain unverified.
Key facts
Timeline
-
First public signal:
?
Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity. -
First public cyber evidence:
?
Earliest credible public information connecting the incident or disruption to malicious cyber activity. -
Official cyber disclosure:
?
First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related. -
Last impact seen:
?
Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing. -
Incident end:
?
Confirmed or defensibly assessed end of material operational disruption or incident activity.
Primary victim organization
Impacted locations
Organization types
Critical infrastructure sector
DysruptionHub coverage
Incident characteristics
Assessments
- Status:
- Resolved
- Incident confidence:
- High
- Ransomware:
- Unresolved
- Attribution:
- Low
DD-CIT classification
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Attack mechanisms
-
Unknown cyber mechanism
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Data impacts
-
Unknown data impact
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Operational impacts
-
Network outage
Internal or external network connectivity was unavailable or materially impaired.
-
Internet access disruption
The organization lost or materially restricted internet connectivity.
-
Phone service disruption
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
-
Government services disrupted
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
-
Alternate service channel required
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Extortion indicators
-
Leak-site listing
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
-
Unknown extortion indicators
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
Incident narrative
Analyst assessment
Prince George County identified a cybersecurity incident after its technology team became aware of computer-system disruptions on or about June 11, 2026. The county’s official notice said it took steps to stop the incident, engaged outside cybersecurity experts and contacted state and federal law enforcement.
DysruptionHub’s published report documented a countywide network outage affecting phones, internet access and online payments. RansomHouse separately claimed that it encrypted the county on June 10 and posted an evidence pack, but the county has not confirmed ransomware, encryption, a ransom demand or RansomHouse responsibility.
Operational significance
The outage affected communications and public-facing payment services across county offices. Water and wastewater payments could not be processed normally, and the county offered late-fee relief. County offices remained open, while 911 and non-emergency dispatch continued to operate; the public record does not establish disruption to critical public-safety services.
The latest dated evidence of continuing recovery was June 17, when the county said the vast majority of systems and services had been restored but limited restoration work remained. The county later stated that its systems were secure and operations had returned to normal.
Disclosure posture
The county’s later notice said perpetrators may have accessed personal information involving current and former employees, dependents, residents and people who interacted with county services. It listed names, addresses, dates of birth, driver’s license numbers and Social Security numbers as types of information the county commonly holds, reported no evidence of misuse and offered free identity monitoring. This establishes a credible potential exposure, not confirmed acquisition or exfiltration.
Current status
Prince George County’s June 24 notice provides an authoritative operational closure: systems were secure and operations had returned to normal. Investigation, law-enforcement cooperation, identity monitoring and security improvements are downstream response activities and do not indicate continuing service disruption.
Confidence and uncertainty
Confidence is high that malicious cyber activity caused material operational disruption because the county confirmed the incident and documented affected services. Data impact remains unresolved because access was described as possible and no public finding confirms that information was acquired or removed. Ransomware confidence remains unresolved, and threat-actor confidence remains low, because the RansomHouse claims are not corroborated by the county, law enforcement, a regulator or independent technical evidence.
Analytic gaps
The reviewed public sources do not establish when malicious activity began, the initial access vector, exploited vulnerability, compromised account, malware family, affected hosts, dwell time, persistence, encryption scope, ransom demand or payment status. They also do not establish whether information was actually copied or exfiltrated, the number of affected people, a final forensic conclusion or attribution.
Threat actor and claim
Claim details
RansomHouse listed Prince George County and claimed the county was encrypted on June 10, 2026, with an evidence pack. The county did not confirm ransomware, encryption, data theft or a ransom demand.

Organizations involved
Prince George County

Locations
Organization type
Critical infrastructure
Impacted locations
Sources
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
DysruptionHub reported that Prince George County confirmed a cybersecurity incident affecting certain systems after countywide phone, internet and online-payment disruptions. Most systems were later restored, while RansomHouse’s encryption and data claims remained unconfirmed.
- Type: Operational Update
- Stance: Confirm
- Platform: Social Platform
- Medium: Web Page
- Confidence: High
Prince George County said a countywide network outage was affecting phone and internet lines across county offices. Offices remained open, but some services could be delayed or temporarily unavailable, while 911 and non-emergency dispatch remained available.
- Type: Operational Update
- Stance: Confirm
- Platform: Social Platform
- Medium: Web Page
- Confidence: High
The county Utilities Department said water and wastewater payments were unavailable during the outage and announced that bills due June 15 would not receive late fees until June 30.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
Prince George County said it became aware of computer-system disruptions on or about June 11, stopped the cybersecurity incident and engaged outside experts. The county said its systems were secure and operations had returned to normal. It warned that perpetrators may have accessed personal information, reported no evidence of misuse and offered free identity monitoring.
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
The June 25 report described the county’s Wednesday, June 24 notice: personal information including names, addresses, dates of birth, driver’s license numbers and Social Security numbers may have been accessed; identity monitoring was offered; systems were secure; and operations had returned to normal.