Town of Lincoln

Encrypted files disrupted Lincoln municipal systems and closed the town office in August 2026. A later forensic investigation found that some town data was potentially acquired, although sensitive-data involvement, notification requirements and misuse remain unresolved.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
The Town of Lincoln disclosed Aug. 16 that its IT provider found encrypted files on portions of the municipal network Aug. 15. Preliminary information indicated the activity may have begun as early as Aug. 13. The town isolated affected systems and described the event as a cybersecurity incident, establishing confirmed cyber involvement.
The encryption and concern about reinfection are consistent with ransomware behavior, but no public victim-specific evidence supports Phobos attribution. The available record does not include a ransom note, encrypted-file extension, contact address, wallet, decryption identifier, malware sample, hash, forensic finding or official, vendor or law-enforcement attribution tying the event to Phobos. Encryption alone cannot distinguish Phobos from other ransomware families or other encryption activity. Ransomware confidence remains medium, while the malware family and responsible actor remain unresolved.
The incident affected several municipal computer systems, including the main file server and other network infrastructure. The town closed the town office Aug. 17 and redirected residents to state online services for registrations, licenses and vital-record requests. Those state services were alternate channels, not affected systems.
The town reopened the office Aug. 18 with limited services. Vehicle registrations, hunting and fishing licenses, tax payments and some property lookups were available while technical recovery continued. A later limited-service update said the office was still operating at limited capacity Aug. 20. The notice was updated to say credit-card payments resumed at 11 a.m. Aug. 21, but it did not announce full restoration.
The affected government serves Lincoln in Penobscot County, Maine. Available notices did not identify impacts to emergency communications, public safety or utilities.
In a Sept. 15 update, the town said independent forensic investigators determined that some data was potentially acquired from its systems. The town was still determining whether sensitive information requiring notification was involved and said it would notify and assist affected people if required. Officials reported no indication that data was being misused, and the investigation remained open.
This supports a qualified data-theft or exfiltration finding but does not establish the data categories, affected people, record count, confirmed sensitive-data exposure or misuse.
Confidence is high that a cyber incident caused encryption and operational disruption because the town documented the encrypted files, containment steps, affected infrastructure, office closure, service redirections and limited-capacity operations. Confidence is medium that ransomware was involved because encryption and reinfection risk are suggestive, but no authority or actor publicly identified ransomware.
Data encryption is confirmed and possible data acquisition is now supported by the town’s forensic update. Sensitive-data involvement, notification obligations and misuse remain under investigation. No stable ransomware or extortion victim claim was identified for the town or lincolnmaine.org.
The incident is presumed operationally resolved. The town was still providing limited service Aug. 21, but its current Town Office page advertised normal weekday hours, card payments and online forms when reviewed Aug. 31. The Sept. 15 update concerned the continuing data investigation and did not document renewed service disruption. This remains an analytic presumption, not a town-issued incident-wide all-clear.
The public record does not establish the initial access vector, malware family, Phobos-specific artifacts, responsible party, exact encryption scope, affected data categories, notification population, ransom demand, negotiation, payment, complete service inventory, forensic findings beyond possible data acquisition or full-restoration date.

Our reporting documented that encrypted municipal network files led Lincoln to isolate systems and close the town office, with residents redirected to state online services while restoration continued. No reopening, full-restoration notice or public claim of responsibility had been identified by publication.
The town announced that the Town Office would be closed Monday, Aug. 17, while recovery from the cybersecurity event continued.
The town said its IT provider found encrypted files on portions of the network, affected systems were isolated and the activity may have begun Aug. 13.
The town closed its office for Aug. 17 and directed residents to state online services for vehicle registrations, hunting and fishing licenses, ATV and boat registrations, and vital-record requests.
Bangor Daily News reported that Lincoln closed its Town Office after encrypted network files were isolated and recovery work began.
The town said the office would reopen Aug. 18 at 8:30 a.m. with limited services while recovery continued. Vehicle registrations, hunting and fishing licenses, tax payments and some property lookups were available.
The town said Aug. 20 that the office was operating at limited capacity. The notice was updated to say credit-card payments resumed at 11 a.m. Aug. 21, but it did not announce full restoration.
The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.
The organization’s official website describes its identity, services, operating role and public or customer-facing programs.
As reviewed Aug. 31, the Town Office page advertised regular weekday hours, acceptance of cash, checks and payment cards, and online municipal forms without a continuing cyber-related limitation or workaround.
Signed-in members can report an error, update, or missing source.