Russell Township Police Department

Geauga County blocked Russell Township Police Department’s email domain on September 8, 2025, after security alerts tied to a police mobile data terminal and school resource officer laptop. The department lost email and full workstation access to Spillman, forcing alternate and hand-delivery workarounds until a government domain became operational November 6, while whether either device was actually compromised remains unresolved.
Only external sources publicly identify the event as cyber-related. The organization publicly documents the resulting service disruption.
The use of deceptive messages or websites to trick people into revealing information, transferring funds or executing malicious content.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
DysruptionHub assesses with high confidence that Geauga County’s cybersecurity containment response caused a prolonged operational disruption at the Russell Township Police Department. County security staff blocked the department’s russellpolice.com email domain Sept. 8, 2025, after a CrowdStrike alert and suspicious DNS activity involving a mobile data terminal and school resource officer laptop. The public record establishes the alerts and response, but it does not establish that either device or any email account was successfully compromised.
The technical evidence remained contested. Official Automatic Data Processing Board minutes say DNS requests, not data, left the police network and that county tools blocked suspicious activity. ADP personnel connected the observations to spoofed phishing email and a possible Microsoft 365 Direct Send issue; the department disabled Direct Send two days after the alert. The police contractor said the activity reflected setup or configuration behavior and that it found no evidence of account or device compromise.
The containment decision eliminated the department’s normal email channel for nearly two months. Police Chief Tom Swaidner said the loss significantly impaired communication with the sheriff’s office, prosecutor, courts and township officials. Officers lacked full Spillman access from workstations and retained access through mobile data terminals, forcing slower alternatives that included physically delivering information to county partners.
The record does not show that dispatch, patrol or emergency response stopped. It does show that a security precaution materially degraded routine law-enforcement administration and time-sensitive justice-system communications.
Confidence is high in the disruption, its Sept. 8 onset and the county’s cyber-response rationale because those facts appear in official meeting records and direct quotations from participating officials. Confidence is lower that an intrusion occurred. The Oct. 9 minutes say no data exfiltration was observed and no email-account compromise was established.
A later follow-up reported that contractor-installed SentinelOne conflicted with county-required CrowdStrike on the mobile terminals. That explanation strengthens the possibility that security tooling or configuration contributed to the alert, but it does not independently explain every DNS observation or produce a public forensic all-clear. The supported mechanism is spoofed phishing associated with Direct Send; user interaction, credential compromise, malware and unauthorized access remain unestablished.
County ADP officials publicly supplied the cyber characterization at a Sept. 18 trustee meeting. The police department documented the operational effects but disputed that its systems were infected or breached. This supports an external cyber characterization with organization-documented disruption rather than an affected-organization acknowledgment of compromise.
The operational disruption is resolved. Township minutes record Swaidner’s Nov. 6 announcement that the department’s new government domain was operational. Trustees later paid a reduced $4,700 county response invoice in February 2026, but that billing dispute was administrative fallout and does not extend the service-impact period.
The public record does not include complete endpoint, DNS or email logs; an independent forensic conclusion; or a definitive explanation reconciling the security-product conflict with the Direct Send observations. It does not establish data access, data theft, ransomware, extortion or threat-actor attribution.

We reported that county containment blocked Russell Township police email for nearly two months after suspicious activity on two police-connected devices. The response impaired justice-system communications and workstation access to Spillman until a government domain became operational Nov. 6; the department’s contractor disputed that the evidence established a compromise.
MacNiven reported that county ADP officials publicly described the issue at a Sept. 18 trustee meeting after alerts on Sept. 8 led the county to isolate police-connected devices and block the department’s email domain. Police Chief Tom Swaidner and the department’s contractor disputed that the activity established a breach, while the chief described impaired communications with courts, law-enforcement partners and township officials.
Official minutes record a CrowdStrike alert, suspicious DNS activity, spoofed phishing email and a possible Microsoft 365 Direct Send issue. ADP said DNS requests, not data, left the police network and sought more logs before lifting the block. The contractor said the observations reflected setup behavior and did not establish email-account or device compromise. The chief said loss of email and full workstation access to Spillman significantly impaired department communications and forced alternate delivery methods.
MacNiven documented the county board’s Oct. 9 decision to maintain the email-domain block, the county’s concern about suspicious DNS and endpoint alerts, the contractor’s disagreement and the police chief’s account of continuing operational workarounds.
The official minutes record Police Chief Tom Swaidner’s statement that the police department’s government domain was operational. The announcement provides the clearest public restoration marker for normal email capability.
MacNiven reported that contractor-installed SentinelOne conflicted with county-required CrowdStrike on the police mobile terminals. Township trustees paid a reduced $4,700 county response invoice Feb. 2, resolving the billing dispute. The report supports a security-tool or configuration contribution to the alert but does not establish a successful intrusion or extend the operational outage beyond November.
Signed-in members can report an error, update, or missing source.