Snyderville Basin Water Reclamation District

Snyderville Basin Water Reclamation District said monitoring detected an intruder encrypting files on an ArcGIS server in December 2025. The district isolated the server and recovered the files; it tentatively associated the event with China and Flax Typhoon, but the attribution and ransomware theory remain unconfirmed.
The organization publicly identifies the event as cyber-related. No credible public source clearly documents service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Unauthorized access to systems, accounts, networks, or data.
Exploitation of a software or hardware vulnerability to gain unauthorized access or execute malicious actions.
Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
Our reporting confirms with high confidence that Snyderville Basin Water Reclamation District experienced unauthorized access and file encryption on an ArcGIS server. The district’s tentative Flax Typhoon attribution is preserved in the narrative as a low-confidence affected-organization claim because the described encryption does not align cleanly with the actor’s publicly documented behavior.
Monitoring detected encryption, and the district isolated the GIS server, recovered files, patched ArcGIS-related issues and expanded monitoring. No interruption to wastewater collection, treatment or water quality was reported.
The documented service-area municipality is Park City in Summit County, Utah. The district’s office uses a Park City address and serves the greater Park City area.
Confidence is high that the ArcGIS server was compromised and files encrypted because the district confirmed both. Ransomware is medium confidence because officials described ransom as a likely objective but reported no actual demand; confidence is low in Flax Typhoon attribution and no public leak-site claim was found.
The district confirmed the cyberattack and explicitly reported no treatment-service disruption, supporting organization-confirmed cyber transparency and no documented material disruption.
The incident is resolved because the district isolated the system and recovered the encrypted files.
The public record does not establish intrusion date, initial access, specific vulnerability, actor, ransom demand, data access or theft, dwell time, forensic basis for attribution or whether more than one actor was present.

We reported the district’s ArcGIS encryption, recovery and tentative Flax Typhoon attribution while noting technical inconsistencies.
Microsoft described Flax Typhoon as a China-based actor focused on stealthy long-term access, not encryption-for-ransom.
District officials said they stopped an international cyberattack and recovered encrypted data.
The district said monitoring detected ArcGIS compromise and encryption, it isolated the server and recovered files.
Signed-in members can report an error, update, or missing source.