Skip to content

Village of Golf Manor Ransomware Incident

Summary

Village of Golf Manor logo

The Village of Golf Manor confirmed that ransomware encrypted its computer network and backups after an intruder accessed the network Nov. 13–14, 2025. The village later said files contained information about employee health plans and began notifying potentially affected people in January 2026.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

  • Data encryption

    Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.

  • Backup compromise

    Backup data or backup systems were accessed, encrypted, deleted, altered, disabled, or otherwise compromised.

Operational impacts

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Encryption-based extortion

    The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.

Incident narrative

Analyst assessment

The Village of Golf Manor’s Nov. 24 draft resolution described a ransomware attack that encrypted its computer network and all available backups. Our Nov. 27 report quoted the village administrator confirming the ransomware incident at a council meeting. That draft was not adopted on Nov. 24. A separate final resolution, marked passed Dec. 8, authorized a ransom payment of up to $10,000 after the council cited restoration and data-breach risks. Authorization does not establish that payment was made.

Operational significance

Encryption of the village network and backups prevented normal use of affected computer systems and complicated restoration. Officials did not identify every public service impaired. Police and 911 disruptions were not reported; the contemporaneous council discussion did not link a separate document-delivery difficulty to the ransomware event. The village’s service area is its municipal boundary, while its administrative office in Golf Manor anchors the affected organization physically.

Data impact and response

A later official privacy notice said an unauthorized party accessed the network Nov. 13–14. On Nov. 28, the village determined that files in its review contained employee health plan information, including names and potentially other personal identifiers and bank details. It began mailing notices Jan. 27, 2026, to certain employees, former employees and dependents. The notice does not state that all listed information was exfiltrated or publicly released.

Current status

The village retained a cybersecurity firm and notified law enforcement. The reviewed sources do not establish when every computer or backup was restored. The last documented operational disruption is from November, so status is presumed resolved without a formal all-clear.

Confidence and uncertainty

Confidence is high in ransomware, network encryption and backup compromise because village records say so. The public record does not identify an actor, initial access vector, complete affected service list, confirmed exfiltration or ransom payment. Council did not approve the Nov. 24 draft, but it passed a later resolution authorizing payment of up to $10,000 on Dec. 8. No reviewed evidence confirms whether money was paid.

Organizations involved

Impacted location

Sources

Ransomware breach hits village of Golf Manor, Ohio

Golf Manor, Ohio, officials say a recent ransomware incident encrypted the village’s computer network and backups, and the council on Nov. 24 reviewed but did not approve a draft resolution that could authorize any ransom payment.

Draft Resolution No. 2025-30 regarding ransomware payment

The Village of Golf Manor became the victim of a cybersecurity ransomware attack which has completed encrypted their computer network including all available data backups.

Notice of Data Privacy Incident

The investigation determined that the unauthorized party accessed the Village of Golf Manor’s computer network between November 13, 2025, and November 14, 2025. On January 27, 2026, we began mailing notification letters to certain current and former employees, and their dependents.

See something that needs correction?

Signed-in members can report an error, update, or missing source.