Skip to content

Snyderville wastewater GIS encryption incident

Summary

Snyderville Basin Water Reclamation District logo

Snyderville Basin Water Reclamation District said monitoring detected an intruder encrypting files on an ArcGIS server in December 2025. The district isolated the server and recovered the files; it tentatively associated the event with China and Flax Typhoon, but the attribution and ransomware theory remain unconfirmed.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. No credible public source clearly documents service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

  • Vulnerability exploitation

    Exploitation of a software or hardware vulnerability to gain unauthorized access or execute malicious actions.

Data impacts

  • Data encryption

    Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

Our reporting confirms with high confidence that Snyderville Basin Water Reclamation District experienced unauthorized access and file encryption on an ArcGIS server. The district’s tentative Flax Typhoon attribution is preserved in the narrative as a low-confidence affected-organization claim because the described encryption does not align cleanly with the actor’s publicly documented behavior.

Operational significance

Monitoring detected encryption, and the district isolated the GIS server, recovered files, patched ArcGIS-related issues and expanded monitoring. No interruption to wastewater collection, treatment or water quality was reported.

The documented service-area municipality is Park City in Summit County, Utah. The district’s office uses a Park City address and serves the greater Park City area.

Confidence and uncertainty

Confidence is high that the ArcGIS server was compromised and files encrypted because the district confirmed both. Ransomware is medium confidence because officials described ransom as a likely objective but reported no actual demand; confidence is low in Flax Typhoon attribution and no public leak-site claim was found.

Disclosure posture

The district confirmed the cyberattack and explicitly reported no treatment-service disruption, supporting organization-confirmed cyber transparency and no documented material disruption.

Current status

The incident is resolved because the district isolated the system and recovered the encrypted files.

Analytic gaps

The public record does not establish intrusion date, initial access, specific vulnerability, actor, ransom demand, data access or theft, dwell time, forensic basis for attribution or whether more than one actor was present.

Organizations involved

Impacted locations

Sources

Utah wastewater district reports GIS server encryption

We reported the district’s ArcGIS encryption, recovery and tentative Flax Typhoon attribution while noting technical inconsistencies.

Flax Typhoon using legitimate software for quiet access

Microsoft described Flax Typhoon as a China-based actor focused on stealthy long-term access, not encryption-for-ransom.

Wastewater district discusses cyberattack

District officials said they stopped an international cyberattack and recovered encrypted data.

Reclamation district says it fended off cyberattack

The district said monitoring detected ArcGIS compromise and encryption, it isolated the server and recovered files.

See something that needs correction?

Signed-in members can report an error, update, or missing source.