Skip to content

USVI Economic Development Authority Ransomware Attack

Summary

U.S. Virgin Islands Economic Development Authority logo

Ransomware locked computer systems at the Virgin Islands Economic Development Authority by Feb. 12, 2026, and prompted a demand exceeding $300,000. Officials investigated whether beneficiary tax records were exposed; no actor, payment or confirmed data theft has been disclosed, and later board activity showed some operations had resumed without establishing an exact restoration date.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Data encryption

    Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Encryption-based extortion

    The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.

  • Direct victim contact

    The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that the U.S. Virgin Islands Economic Development Authority experienced ransomware. We reported that its computer systems were locked and attackers demanded more than $300,000. Gov. Albert Bryan Jr. confirmed Feb. 12 that the systems remained locked while the authority, its cyber insurer and the FBI worked to restore access.

Operational significance

The outage denied the authority access to internal computer systems. The public record does not identify the affected applications or establish interruption to tax-incentive applications, lending, payments or another public-facing service. The authority has offices in Frederiksted on St. Croix and Charlotte Amalie on St. Thomas, but no source distinguishes the impact at either office.

Confidence and uncertainty

Ransomware is confirmed by the documented system lockout and payment demand. Officials were assessing whether beneficiary information, including tax-related documents, had been accessed, but no public notice through Aug. 24 confirmed exposure, record counts or notifications. No named actor claim was found in the reviewed public claim indexes, and payment remains unresolved.

Disclosure posture

The first accessible public report on Feb. 12 included the governor’s cyber-specific confirmation and described locked systems, supporting organization-confirmed cyber and disruption transparency. The authority itself had not issued a statement by publication.

Current status

The governor said systems were still locked Feb. 12, the latest supported operational-impact date. The authority’s board processed application matters March 19, showing that at least some core functions had resumed, but the agency has not published a final all-clear or exact restoration date. The incident is therefore presumed resolved rather than confirmed resolved.

Analytic gaps

The public record does not establish when the intrusion began, initial access, ransomware family, encryption scope, affected applications, data access or exfiltration, ransom payment, restoration method, exact recovery date, actor or notification population.

Organizations involved

Impacted locations

Sources

Ransomware hits USVI Economic Development Authority

We reported that ransomware locked authority computer systems, prompted a demand exceeding $300,000 and led officials to investigate possible data exposure.

Hackers Lock EDA Systems, Demand Over $300,000 in Ransom

The Virgin Islands Consortium reported that Gov. Albert Bryan Jr. confirmed the attack, said authority systems remained locked and described a ransom demand exceeding $300,000. Officials were assessing whether beneficiary tax-related documents had been compromised.

Virgin Islands Economic Development Commission Decision Meeting of Thursday, March 19, 2026 Summary Report

The official summary records the authority’s board hearing and voting on application matters March 19, demonstrating that at least some core program activity had resumed without providing a full system-restoration date.

USVIEDA

The authority describes its economic-development, tax-incentive and financing programs and lists offices in Frederiksted and St. Thomas.

See something that needs correction?

Signed-in members can report an error, update, or missing source.