Town of Clayton, North Carolina

Clayton detected suspicious network activity on one system March 18 and manually took its network offline, limiting phones and online services during restoration. By March 23, investigators said attempted data access was unsuccessful and found no evidence that customer or employee data was compromised. No stable public actor claim was identified, and no later continuing impact was found.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Available evidence indicates that the incident did not materially affect the confidentiality, integrity, or availability of data.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
Clayton detected suspicious network activity on one system March 18, 2026, and manually took its network offline to contain the activity. The town’s March 23 statement said investigators determined that the event did not escalate into a full cybersecurity incident, attempted data access was unsuccessful and no customer or employee data was known to be compromised. The documented suspicious activity and attempted access provide concrete cyber evidence, but the public record does not establish the specific mechanism.
Town offices maintained normal business hours, but the containment shutdown and restoration work limited phones and several online systems. Those service effects remained documented March 23. The affected geography is Clayton in Johnston County, North Carolina.
The incident is presumed resolved. Clayton was still restoring systems March 23, but no later continuing operational impact was found. The public record does not provide a final full-restoration date.
Confidence is high that suspicious network activity and the protective shutdown caused a municipal service disruption. No known data impact is supported by the town’s findings. Ransomware and attribution remain unresolved: searches using Clayton’s canonical name and townofclaytonnc.org found no stable public actor claim, and the town did not identify ransomware or an extortion demand.
The public record does not establish the access vector, affected host, malicious tooling, persistence, responsible actor or final restoration date.

Suspicious activity on one system prompted Clayton to take parts of its network offline, affecting phones and some online services.
Clayton said suspicious activity detected March 18 prompted a network shutdown. On March 23, some services remained limited, attempted data access was assessed as unsuccessful and no customer or employee data compromise was found.
The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.
The organization’s official website describes its identity, services, operating role and public or customer-facing programs.
Signed-in members can report an error, update, or missing source.