Skip to content

Prince George County cyber incident disrupted services

Summary

Prince George County, Virginia, said a June 11, 2026 cyber incident disrupted phones, internet and online payments before systems were secured and normal operations resumed. The county said personal data may have been accessed and offered identity monitoring, while RansomHouse’s ransomware and attribution claims remain unverified.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Incident characteristics

Assessments

Status:
Resolved
Incident confidence:
High
Ransomware:
Unresolved
Attribution:
Low

DD-CIT classification

OC-ODOfficial cyberOfficial disruptionAbout the DD-CIT methodology

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internet access disruption

    The organization lost or materially restricted internet connectivity.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

Prince George County identified a cybersecurity incident after its technology team became aware of computer-system disruptions on or about June 11, 2026. The county’s official notice said it took steps to stop the incident, engaged outside cybersecurity experts and contacted state and federal law enforcement.

DysruptionHub’s published report documented a countywide network outage affecting phones, internet access and online payments. RansomHouse separately claimed that it encrypted the county on June 10 and posted an evidence pack, but the county has not confirmed ransomware, encryption, a ransom demand or RansomHouse responsibility.

Operational significance

The outage affected communications and public-facing payment services across county offices. Water and wastewater payments could not be processed normally, and the county offered late-fee relief. County offices remained open, while 911 and non-emergency dispatch continued to operate; the public record does not establish disruption to critical public-safety services.

The latest dated evidence of continuing recovery was June 17, when the county said the vast majority of systems and services had been restored but limited restoration work remained. The county later stated that its systems were secure and operations had returned to normal.

Disclosure posture

The county’s later notice said perpetrators may have accessed personal information involving current and former employees, dependents, residents and people who interacted with county services. It listed names, addresses, dates of birth, driver’s license numbers and Social Security numbers as types of information the county commonly holds, reported no evidence of misuse and offered free identity monitoring. This establishes a credible potential exposure, not confirmed acquisition or exfiltration.

Current status

Prince George County’s June 24 notice provides an authoritative operational closure: systems were secure and operations had returned to normal. Investigation, law-enforcement cooperation, identity monitoring and security improvements are downstream response activities and do not indicate continuing service disruption.

Confidence and uncertainty

Confidence is high that malicious cyber activity caused material operational disruption because the county confirmed the incident and documented affected services. Data impact remains unresolved because access was described as possible and no public finding confirms that information was acquired or removed. Ransomware confidence remains unresolved, and threat-actor confidence remains low, because the RansomHouse claims are not corroborated by the county, law enforcement, a regulator or independent technical evidence.

Analytic gaps

The reviewed public sources do not establish when malicious activity began, the initial access vector, exploited vulnerability, compromised account, malware family, affected hosts, dwell time, persistence, encryption scope, ransom demand or payment status. They also do not establish whether information was actually copied or exfiltrated, the number of affected people, a final forensic conclusion or attribution.

Threat actor and claim

Listed as: Prince George CountySource: ransomware.liveDiscovered:

Claim details

RansomHouse listed Prince George County and claimed the county was encrypted on June 10, 2026, with an evidence pack. The county did not confirm ransomware, encryption, data theft or a ransom demand.

Screenshot documenting RansomHouse claim

Organizations involved

Impacted locations

Sources

Prince George County, Virginia, restores most systems after cyber incident
DysruptionHubBy Joseph ToppingPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

DysruptionHub reported that Prince George County confirmed a cybersecurity incident affecting certain systems after countywide phone, internet and online-payment disruptions. Most systems were later restored, while RansomHouse’s encryption and data claims remained unconfirmed.

Prince George County network outage notices
Prince George CountyPublished: Retrieved:
  • Type: Operational Update
  • Stance: Confirm
  • Platform: Social Platform
  • Medium: Web Page
  • Confidence: High

Prince George County said a countywide network outage was affecting phone and internet lines across county offices. Offices remained open, but some services could be delayed or temporarily unavailable, while 911 and non-emergency dispatch remained available.

Prince George County Utilities payment outage notice
Prince George CountyPublished: Retrieved:
  • Type: Operational Update
  • Stance: Confirm
  • Platform: Social Platform
  • Medium: Web Page
  • Confidence: High

The county Utilities Department said water and wastewater payments were unavailable during the outage and announced that bills due June 15 would not receive late fees until June 30.

Notice of Cyber Incident
Prince George County, VirginiaPublished: Retrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

Prince George County said it became aware of computer-system disruptions on or about June 11, stopped the cybersecurity incident and engaged outside experts. The county said its systems were secure and operations had returned to normal. It warned that perpetrators may have accessed personal information, reported no evidence of misuse and offered free identity monitoring.

Prince George County, Va., Discloses Recent Cyber Attack
Richmond Times-Dispatch via Government TechnologyBy Gwyndolyn MilesPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

The June 25 report described the county’s Wednesday, June 24 notice: personal information including names, addresses, dates of birth, driver’s license numbers and Social Security numbers may have been accessed; identity monitoring was offered; systems were secure; and operations had returned to normal.