Skip to content

Russell Township Police Email Disruption

Summary

Russell Township Police Department logo

Geauga County blocked Russell Township Police Department’s email domain on September 8, 2025, after security alerts tied to a police mobile data terminal and school resource officer laptop. The department lost email and full workstation access to Spillman, forcing alternate and hand-delivery workarounds until a government domain became operational November 6, while whether either device was actually compromised remains unresolved.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

Only external sources publicly identify the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Phishing

    The use of deceptive messages or websites to trick people into revealing information, transferring funds or executing malicious content.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Geauga County’s cybersecurity containment response caused a prolonged operational disruption at the Russell Township Police Department. County security staff blocked the department’s russellpolice.com email domain Sept. 8, 2025, after a CrowdStrike alert and suspicious DNS activity involving a mobile data terminal and school resource officer laptop. The public record establishes the alerts and response, but it does not establish that either device or any email account was successfully compromised.

The technical evidence remained contested. Official Automatic Data Processing Board minutes say DNS requests, not data, left the police network and that county tools blocked suspicious activity. ADP personnel connected the observations to spoofed phishing email and a possible Microsoft 365 Direct Send issue; the department disabled Direct Send two days after the alert. The police contractor said the activity reflected setup or configuration behavior and that it found no evidence of account or device compromise.

Operational significance

The containment decision eliminated the department’s normal email channel for nearly two months. Police Chief Tom Swaidner said the loss significantly impaired communication with the sheriff’s office, prosecutor, courts and township officials. Officers lacked full Spillman access from workstations and retained access through mobile data terminals, forcing slower alternatives that included physically delivering information to county partners.

The record does not show that dispatch, patrol or emergency response stopped. It does show that a security precaution materially degraded routine law-enforcement administration and time-sensitive justice-system communications.

Confidence and uncertainty

Confidence is high in the disruption, its Sept. 8 onset and the county’s cyber-response rationale because those facts appear in official meeting records and direct quotations from participating officials. Confidence is lower that an intrusion occurred. The Oct. 9 minutes say no data exfiltration was observed and no email-account compromise was established.

A later follow-up reported that contractor-installed SentinelOne conflicted with county-required CrowdStrike on the mobile terminals. That explanation strengthens the possibility that security tooling or configuration contributed to the alert, but it does not independently explain every DNS observation or produce a public forensic all-clear. The supported mechanism is spoofed phishing associated with Direct Send; user interaction, credential compromise, malware and unauthorized access remain unestablished.

Disclosure posture

County ADP officials publicly supplied the cyber characterization at a Sept. 18 trustee meeting. The police department documented the operational effects but disputed that its systems were infected or breached. This supports an external cyber characterization with organization-documented disruption rather than an affected-organization acknowledgment of compromise.

Current status

The operational disruption is resolved. Township minutes record Swaidner’s Nov. 6 announcement that the department’s new government domain was operational. Trustees later paid a reduced $4,700 county response invoice in February 2026, but that billing dispute was administrative fallout and does not extend the service-impact period.

Analytic gaps

The public record does not include complete endpoint, DNS or email logs; an independent forensic conclusion; or a definitive explanation reconciling the security-product conflict with the Direct Send observations. It does not establish data access, data theft, ransomware, extortion or threat-actor attribution.

Organizations involved

Impacted location

Sources

Russell Township police email cut off for weeks after suspected intrusion flagged in Ohio county network

We reported that county containment blocked Russell Township police email for nearly two months after suspicious activity on two police-connected devices. The response impaired justice-system communications and workstation access to Spillman until a government domain became operational Nov. 6; the department’s contractor disputed that the evidence established a compromise.

Suspected Breach Triggers Stalemate Between Russell P.D. and ADP

MacNiven reported that county ADP officials publicly described the issue at a Sept. 18 trustee meeting after alerts on Sept. 8 led the county to isolate police-connected devices and block the department’s email domain. Police Chief Tom Swaidner and the department’s contractor disputed that the activity established a breach, while the chief described impaired communications with courts, law-enforcement partners and township officials.

October 9, 2025, ADP Board Special Meeting

Official minutes record a CrowdStrike alert, suspicious DNS activity, spoofed phishing email and a possible Microsoft 365 Direct Send issue. ADP said DNS requests, not data, left the police network and sought more logs before lifting the block. The contractor said the observations reflected setup behavior and did not establish email-account or device compromise. The chief said loss of email and full workstation access to Spillman significantly impaired department communications and forced alternate delivery methods.

Russell Police Email Remains Blocked Amid Security Dispute

MacNiven documented the county board’s Oct. 9 decision to maintain the email-domain block, the county’s concern about suspicious DNS and endpoint alerts, the contractor’s disagreement and the police chief’s account of continuing operational workarounds.

Russell Township Trustees Regular Meeting Minutes, November 6, 2025

The official minutes record Police Chief Tom Swaidner’s statement that the police department’s government domain was operational. The announcement provides the clearest public restoration marker for normal email capability.

Russell Township, ADP Resolve Dispute After 6 Months

MacNiven reported that contractor-installed SentinelOne conflicted with county-required CrowdStrike on the police mobile terminals. Township trustees paid a reduced $4,700 county response invoice Feb. 2, resolving the billing dispute. The report supports a security-tool or configuration contribution to the alert but does not establish a successful intrusion or extend the operational outage beyond November.

See something that needs correction?

Signed-in members can report an error, update, or missing source.