Skip to content

Spartanburg County network outage disrupted services

Summary

Spartanburg County, South Carolina logo

Spartanburg County isolated portions of its network after detecting questionable activity on its computer infrastructure June 10, 2026, disrupting phones, courts, payments and records for nearly three weeks. Officials never publicly labeled the event a cybersecurity incident or confirmed malicious access, but the county’s system-activity and security-response wording provides concrete cyber evidence under registry criteria. Core connectivity returned June 29, and operations are presumed resolved.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internet access disruption

    The organization lost or materially restricted internet connectivity.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Payment processing disruption

    The organization could not process, receive, issue, reconcile, or record payments normally.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

Spartanburg County isolated portions of its computer environment after detecting questionable activity on June 10, 2026. Our June 15 report documented the multi-day network and internet outage while the South Carolina Law Enforcement Division’s critical-infrastructure cybersecurity unit assisted.

The county never publicly labeled the event a cybersecurity incident or cyberattack. It also did not confirm malicious or unauthorized access. However, its acknowledgement of questionable activity on county computer infrastructure, precautionary network isolation, additional security checks and a SLED cybersecurity investigation is concrete cyber-specific evidence under registry policy. The registry therefore retains confirmed cyber involvement, a narrower finding than confirmation that an attacker caused the incident.

Operational significance

The outage materially affected county government for nearly three weeks. WYFF reported disruption to phones, computers, court functions and records access. Some offices could not process card payments or provide licensing and deed documents, sheriff’s personnel used handwritten reports, and staff relied on personal or alternative resources to answer requests.

The county said core network services and employee connectivity were restored June 29. That update was not an unqualified all-clear: officials said some services could continue to experience isolated delays while devices and applications reconnected and systems were validated and returned fully to normal operation.

Current status

Operations are presumed resolved. By Aug. 3, the county’s former outage alert returned a 404 page, the regular county website displayed routine government information and its Citizen Self Service link was available. A Sept. 3 review found no later county notice or credible report documenting continuing delays, unavailable systems, manual workarounds or restoration activity.

June 29 remains the latest confirmed date of operational impact because the county said residual delays could continue on that date. The absence of newer impact evidence and the county’s normal public-web posture support presumed resolution. The status is not resolved because no retrospective all-clear identified when the last isolated issue or validation work ended.

Disclosure posture

On June 12, FITSNews reported that SLED’s South Carolina Critical Infrastructure Cybersecurity unit was assisting and its investigation was active. That established a cyber-response context, but the reported facts still described an unexplained outage and did not assert that malicious cyber activity had occurred. The county’s own June 12 notice also contained only outage language. Neither constitutes XC.

The first qualifying concrete cyber evidence came from the county June 22. It told WYFF that it had detected questionable activity on its computer infrastructure and isolated its networks to protect them while security work proceeded. Because the first qualifying cyber-specific disclosure came from the affected organization, the cyber-transparency classification is OC.

The county’s June 29 statement, reproduced by FOX Carolina, said it had not identified evidence that data was accessed, exfiltrated or compromised. The security review was still ongoing. No final review, later breach notice, regulator filing, affected-data category or affected-person count has been published for this event.

Confidence and uncertainty

Confidence is high that the event caused material operational disruption. Overall incident confidence remains medium because the county documented suspicious system activity and a cybersecurity response but did not disclose a final cause or confirm a malicious intrusion. The county’s security-response wording supports confirmed cyber involvement under the registry definition; the earlier presence of SLED’s cyber unit does not independently prove cyber activity, and neither establishes a completed attack.

Confidentiality and integrity impacts remain unresolved. The county’s no-data-compromise statement is an important interim finding, but no completed security-review conclusion has been published. Ransomware and threat-actor attribution also remain unresolved; no encryption, demand, leak-site claim, payment or responsible actor has been identified.

Analytic gaps

The public record does not establish the triggering activity, whether it was malicious, the initial access vector, affected hosts, vulnerability, compromised account, malware, persistence or whether attacker activity rather than defensive isolation caused each service effect. It also does not provide a final security-review conclusion, a system-by-system all-clear or the date when the last isolated service delay ended.

Organizations involved

Impacted locations

Sources

Spartanburg County outage draws cyber response

We reported that Spartanburg County offices remained open during a multi-day network and internet outage that disrupted services and communications while SLED cybersecurity officials assisted. At publication, officials had not confirmed a cyberattack, ransomware, data theft, a ransom demand or a threat actor.

SLED investigates Spartanburg County network outage

WYFF reported that internet-dependent systems had been unavailable for nearly two weeks, including computer services and phone access. County offices remained open, while employees used workarounds and court staff could not reliably access records and information outside local systems.

Spartanburg County restores network, reports no data compromise

WYFF reported that Spartanburg County restored core network services and employee connectivity June 29, but the county said some services could continue to experience isolated delays while systems were validated and brought fully back to normal. The security review remained ongoing, with no identified evidence of data access, exfiltration or compromise.

Officials: Spartanburg County network services restored following outage

FOX Carolina reported that core network services were restored, but the county said isolated issues and service delays could continue while devices and applications reconnected and systems returned fully to normal. The security review remained ongoing, and officials had not identified evidence of data access, exfiltration or compromise.

Spartanburg County, South Carolina official website

The county’s regular website was functioning August 3, displayed routine county news and linked to Citizen Self Service without the earlier network-outage alert or a continuing-impact notice.

See something that needs correction?

Signed-in members can report an error, update, or missing source.