Claim details
RansomHouse listed Prince George County and claimed the county was encrypted on June 10, 2026, with an evidence pack. The county did not confirm ransomware, encryption, data theft or a ransom demand.

Prince George County, Virginia, said a June 11, 2026 cyber incident disrupted phones, internet and online payments before systems were secured and normal operations resumed. The county said personal data may have been accessed and offered identity monitoring, while RansomHouse’s ransomware and attribution claims remain unverified.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Internal or external network connectivity was unavailable or materially impaired.
The organization lost or materially restricted internet connectivity.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
Prince George County identified a cybersecurity incident after its technology team became aware of computer-system disruptions on or about June 11, 2026. The county’s official notice said it took steps to stop the incident, engaged outside cybersecurity experts and contacted state and federal law enforcement.
DysruptionHub’s published report documented a countywide network outage affecting phones, internet access and online payments. RansomHouse separately claimed that it encrypted the county on June 10 and posted an evidence pack, but the county has not confirmed ransomware, encryption, a ransom demand or RansomHouse responsibility.
The outage affected communications and public-facing payment services across county offices. Water and wastewater payments could not be processed normally, and the county offered late-fee relief. County offices remained open, while 911 and non-emergency dispatch continued to operate; the public record does not establish disruption to critical public-safety services.
The latest dated evidence of continuing recovery was June 17, when the county said the vast majority of systems and services had been restored but limited restoration work remained. The county later stated that its systems were secure and operations had returned to normal.
The county’s later notice said perpetrators may have accessed personal information involving current and former employees, dependents, residents and people who interacted with county services. It listed names, addresses, dates of birth, driver’s license numbers and Social Security numbers as types of information the county commonly holds, reported no evidence of misuse and offered free identity monitoring. This establishes a credible potential exposure, not confirmed acquisition or exfiltration.
Prince George County’s June 24 notice provides an authoritative operational closure: systems were secure and operations had returned to normal. Investigation, law-enforcement cooperation, identity monitoring and security improvements are downstream response activities and do not indicate continuing service disruption.
Confidence is high that malicious cyber activity caused material operational disruption because the county confirmed the incident and documented affected services. Data impact remains unresolved because access was described as possible and no public finding confirms that information was acquired or removed. Ransomware confidence remains unresolved, and threat-actor confidence remains low, because the RansomHouse claims are not corroborated by the county, law enforcement, a regulator or independent technical evidence.
The reviewed public sources do not establish when malicious activity began, the initial access vector, exploited vulnerability, compromised account, malware family, affected hosts, dwell time, persistence, encryption scope, ransom demand or payment status. They also do not establish whether information was actually copied or exfiltrated, the number of affected people, a final forensic conclusion or attribution.
RansomHouse listed Prince George County and claimed the county was encrypted on June 10, 2026, with an evidence pack. The county did not confirm ransomware, encryption, data theft or a ransom demand.


DysruptionHub reported that Prince George County confirmed a cybersecurity incident affecting certain systems after countywide phone, internet and online-payment disruptions. Most systems were later restored, while RansomHouse’s encryption and data claims remained unconfirmed.
Prince George County said a countywide network outage was affecting phone and internet lines across county offices. Offices remained open, but some services could be delayed or temporarily unavailable, while 911 and non-emergency dispatch remained available.
The county Utilities Department said water and wastewater payments were unavailable during the outage and announced that bills due June 15 would not receive late fees until June 30.
Prince George County said it became aware of computer-system disruptions on or about June 11, stopped the cybersecurity incident and engaged outside experts. The county said its systems were secure and operations had returned to normal. It warned that perpetrators may have accessed personal information, reported no evidence of misuse and offered free identity monitoring.
The June 25 report described the county’s Wednesday, June 24 notice: personal information including names, addresses, dates of birth, driver’s license numbers and Social Security numbers may have been accessed; identity monitoring was offered; systems were secure; and operations had returned to normal.
Signed-in members can report an error, update, or missing source.