Spartanburg County network outage disrupted services
Summary
Spartanburg County isolated portions of its network after detecting questionable activity around June 10, 2026, causing weeks of disruption to phones, courts, payments, records and other services. Core connectivity returned June 29, but isolated delays could continue during validation; officials found no evidence of data compromise and did not confirm ransomware or an actor.
Key facts
Timeline
-
Incident start:
?
Earliest known or assessed start of malicious activity or incident activity. -
First public signal:
?
Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity. -
First public cyber evidence:
?
Earliest credible public information connecting the incident or disruption to malicious cyber activity. -
Official cyber disclosure:
?
First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related. -
Last impact seen:
?
Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
Primary victim organization
Impacted locations
Organization types
Critical infrastructure sector
DysruptionHub coverage
Incident characteristics
Assessments
- Status:
- Presumed Active
- Incident confidence:
- Medium
- Ransomware:
- Unresolved
DD-CIT classification
External sources identified the event as cyber-related before the organization publicly confirmed it. The organization publicly documents the resulting service disruption.
Attack mechanisms
-
Unknown cyber mechanism
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Data impacts
-
Data unavailable
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Operational impacts
-
Network outage
Internal or external network connectivity was unavailable or materially impaired.
-
Internet access disruption
The organization lost or materially restricted internet connectivity.
-
Phone service disruption
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
-
Internal systems unavailable
Internal business, administrative, operational, or staff-facing systems were unavailable.
-
Government services disrupted
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
-
Manual workaround required
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
-
Payment processing disruption
The organization could not process, receive, issue, reconcile, or record payments normally.
-
Records access disruption
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
-
Records processing disruption
The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.
-
Customer or public access restricted
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Extortion indicators
-
No known extortion indicator
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
Incident narrative
Analyst assessment
Spartanburg County isolated portions of its computer environment after detecting activity that warranted further review around June 10, 2026. DysruptionHub’s published report documented a multi-day network and internet outage while the South Carolina Law Enforcement Division’s critical-infrastructure cybersecurity unit assisted.
DysruptionHub assesses with medium confidence that the event involved malicious or unauthorized cyber activity. The county’s isolation and security-review response, together with the state cybersecurity investigation, support a suspected cyber incident, but officials have not confirmed an intrusion, malware, ransomware or another attack mechanism.
Operational significance
The outage materially affected county government for nearly three weeks. WYFF reported disruption to phones, computers, court functions and records access. Some offices could not process card payments or provide licensing and deed documents, sheriff’s personnel used handwritten reports, and staff relied on personal or alternative resources to answer requests.
Core network availability returned, but restoration was not an unqualified all-clear. The county said employee connectivity had resumed while some services could still experience isolated delays as devices and applications were validated and brought fully back into normal operation.
Disclosure posture
The county consistently described questionable activity, precautionary isolation and a security review rather than a confirmed cyberattack. That caution is analytically material: the public record establishes a cyber-response context and substantial disruption, but it does not establish malicious access, a specific technique or responsibility for the event.
Current status
The county’s June 29 statement, independently reported by FOX Carolina, said core services were restored but isolated delays could continue while systems returned fully to normal. No later full-restoration notice was found by July 26. The incident is therefore presumed active under the operational-impact lifecycle, reflecting the age of the last documented residual impact rather than evidence of a renewed outage.
Confidence and uncertainty
Confidence is high that the event caused material operational disruption, but medium that malicious cyber activity caused it because no confirmed intrusion or attack type has been disclosed. The county said it had not identified evidence that data was accessed, exfiltrated or compromised, although its security review remained ongoing. Ransomware and threat-actor attribution remain unresolved; no encryption, demand, leak-site claim, payment or responsible actor has been identified.
Analytic gaps
The reviewed sources do not establish the triggering activity, initial access vector, affected hosts, vulnerability, compromised account, malware, persistence or whether attacker activity versus defensive isolation caused each service effect. They also do not provide a final security-review conclusion, a system-by-system all-clear or a date when the last isolated service delay ended.
Organizations involved
Spartanburg County, South Carolina

Locations
Organization type
Critical infrastructure
Impacted locations
Sources
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
DysruptionHub reported that Spartanburg County offices remained open during a multi-day network and internet outage that disrupted services and communications while SLED cybersecurity officials assisted. The county had not publicly confirmed ransomware or another specific attack type.
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
WYFF reported that internet-dependent systems had been unavailable for nearly two weeks, including computer services and phone access. County offices remained open, while employees used workarounds and court staff could not reliably access records and information outside local systems.
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
WYFF reported that Spartanburg County restored core network services and employee connectivity June 29, but the county said some services could continue to experience isolated delays while systems were validated and brought fully back to normal. The security review remained ongoing, with no identified evidence of data access, exfiltration or compromise.
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
FOX Carolina reported that core network services were restored, but the county said isolated issues and service delays could continue while devices and applications reconnected and systems returned fully to normal. The security review remained ongoing, and officials had not identified evidence of data access, exfiltration or compromise.