Spartanburg County, South Carolina

Spartanburg County isolated portions of its network after detecting questionable activity around June 10, 2026, causing weeks of disruption to phones, courts, payments, records and other services. Core connectivity returned June 29, and by August 3 the outage alert was gone with no later impact report found, so operations are presumed resolved. Officials did not confirm an intrusion, data compromise, ransomware or an actor.
External sources identified the event as cyber-related before the organization publicly confirmed it. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Internal or external network connectivity was unavailable or materially impaired.
The organization lost or materially restricted internet connectivity.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The organization could not process, receive, issue, reconcile, or record payments normally.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
Spartanburg County isolated portions of its computer environment after detecting activity that warranted further review around June 10, 2026. DysruptionHub’s published report documented a multi-day network and internet outage while the South Carolina Law Enforcement Division’s critical-infrastructure cybersecurity unit assisted.
DysruptionHub assesses with medium confidence that the event involved malicious or unauthorized cyber activity. The county’s isolation and security-review response, together with the state cybersecurity investigation, support a suspected cyber incident, but officials have not confirmed an intrusion, malware, ransomware or another attack mechanism.
The outage materially affected county government for nearly three weeks. WYFF reported disruption to phones, computers, court functions and records access. Some offices could not process card payments or provide licensing and deed documents, sheriff’s personnel used handwritten reports, and staff relied on personal or alternative resources to answer requests.
The county said core network services and employee connectivity were restored June 29. That update was not an unqualified all-clear: officials said some services could continue to experience isolated delays while devices and applications reconnected and systems were validated and brought fully back into normal operation.
Operations are presumed resolved. By August 3, the county’s former outage alert returned a 404 page, the regular county website displayed routine government information and its Citizen Self Service link was available. No later county notice or credible report documented continuing delays, unavailable systems, manual workarounds or restoration activity.
June 29 remains the latest confirmed date of operational impact because the county said residual delays could continue on that date. More than 30 days later, the absence of newer impact evidence and the county’s normal public-web posture support presumed resolution. The status is not resolved because no retrospective all-clear identified when the last isolated issue or validation work ended.
The county consistently described questionable activity, precautionary isolation and a security review rather than a confirmed cyberattack. That caution is analytically material: the public record establishes a cyber-response context and substantial disruption, but it does not establish malicious access, a specific technique or responsibility for the event.
The June 29 county statement, reproduced by FOX Carolina, said officials had not identified evidence that data was accessed, exfiltrated or compromised. The security review was still ongoing in that update. As of August 3, no final review, later breach notice, regulator filing, affected-data category or affected-person count had been found for this event.
Confidence is high that the event caused material operational disruption, but medium that malicious cyber activity caused it because no confirmed intrusion or attack type has been disclosed. SLED cybersecurity involvement and the county’s response are significant indicators, not proof of a completed malicious intrusion.
Confidentiality and integrity impacts remain unresolved. The county’s no-data-compromise statement is an important interim finding, but no completed security-review conclusion has been published. Ransomware and threat-actor attribution also remain unresolved; no encryption, demand, leak-site claim, payment or responsible actor has been identified.
The reviewed sources do not establish the triggering activity, initial-access vector, affected hosts, vulnerability, compromised account, malware, persistence or whether attacker activity versus defensive isolation caused each service effect. They also do not provide a final security-review conclusion, a system-by-system all-clear or the date when the last isolated service delay ended.
A later forensic report, breach notice, actor claim or retrospective restoration statement could materially change the assessment.

The county’s regular website was functioning August 3, displayed routine county news and linked to Citizen Self Service without the earlier network-outage alert or a continuing-impact notice.
DysruptionHub reported that Spartanburg County offices remained open during a multi-day network and internet outage that disrupted services and communications while SLED cybersecurity officials assisted. The county had not publicly confirmed ransomware or another specific attack type.
WYFF reported that internet-dependent systems had been unavailable for nearly two weeks, including computer services and phone access. County offices remained open, while employees used workarounds and court staff could not reliably access records and information outside local systems.
WYFF reported that Spartanburg County restored core network services and employee connectivity June 29, but the county said some services could continue to experience isolated delays while systems were validated and brought fully back to normal. The security review remained ongoing, with no identified evidence of data access, exfiltration or compromise.
FOX Carolina reported that core network services were restored, but the county said isolated issues and service delays could continue while devices and applications reconnected and systems returned fully to normal. The security review remained ongoing, and officials had not identified evidence of data access, exfiltration or compromise.
Signed-in members can report an error, update, or missing source.