Wise County Sheriff’s Office cyberattack disrupts records access
Summary
The Wise County Sheriff’s Office said hackers hit its systems twice during the week before June 22, 2026, preventing records retrieval and printing of incoming public-information requests. Logged and saved requests were lost or inaccessible and had to be rebuilt from sent email files. The deadline suspension ended July 5 and official request channels are currently available, but full restoration and recovery of missing requests remain unconfirmed.
Key facts
Timeline
-
First public signal:
?
Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity. -
First public cyber evidence:
?
Earliest credible public information connecting the incident or disruption to malicious cyber activity. -
Official cyber disclosure:
?
First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related. -
Last impact seen:
?
Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
Primary victim organization
DysruptionHub coverage
Impacted locations
Organization types
Critical infrastructure sector
Incident characteristics
Assessments
- Status:
- Presumed Resolved
- Incident confidence:
- High
- Ransomware:
- Unresolved
DD-CIT classification
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Attack mechanisms
-
Unknown cyber mechanism
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Data impacts
-
Data unavailable
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Operational impacts
-
Partial service outage
A service, system, platform, or operational capability remained available only in part or with significant limitations.
-
Internal systems unavailable
Internal business, administrative, operational, or staff-facing systems were unavailable.
-
Records access disruption
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
-
Records processing disruption
The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.
-
Government services disrupted
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
-
Service delay
Services continued but with longer processing, response, delivery, or completion times.
-
Backlog created
The disruption caused an accumulation of unprocessed requests, cases, orders, records, appointments, or other work.
-
Manual workaround required
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
-
Staff unable to work normally
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
-
Customer or public access restricted
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Extortion indicators
-
No known extortion indicator
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
Incident narrative
Analyst assessment
DysruptionHub assesses with high confidence that the Wise County Sheriff’s Office experienced malicious cyber activity that materially disrupted records operations in June 2026. In a June 22 catastrophe notice, the office said all systems had been hit twice by hackers during the preceding week. Staff could not retrieve records or print incoming public-information requests, and logged and saved requests were gone or inaccessible.
The filing narrows both attacks only to the week before June 22; it does not identify either attack date. The evidence confirms malicious cyber activity but not its mechanism. No public source identifies initial access, a compromised account, an exploited vulnerability, malware, encryption, data exfiltration or a responsible threat actor. No ransomware confirmation or ransom demand was found.
Operational significance
The disruption directly affected compliance with the Texas Public Information Act. The office said requests would have to be rebuilt from fulfilled-request records retained in sent email files, indicating loss of normal records access, delayed processing and a manual reconstruction burden. It warned that some missing material might never be retrieved.
The sheriff’s office suspended public-information deadlines from June 22 through June 28. A second catastrophe notice extended the suspension through July 5, showing that the operational effect continued beyond the initial period. The current Texas attorney general register contains no later Wise County Sheriff’s Office extension.
The confirmed impact is administrative and records-related. The public record does not establish whether 911, dispatch, patrol, detention, communications, evidence management or other public-safety functions were disrupted. Those effects cannot be inferred from the broader statement that all systems were hit.
Disclosure posture
The clearest disclosure came through notices filed with the Texas attorney general rather than a detailed public-facing incident update. DysruptionHub’s published report documented the notices, the extension through July 5 and the absence of public answers about ransomware, data theft, attribution and public-safety effects.
The notices acknowledge malicious activity and operational disruption but provide little technical or recovery detail. No later breach notice, affected-data disclosure or forensic conclusion was found. That absence does not establish that no data was accessed; confidentiality and integrity effects remain unresolved.
Current status
The June 22 notice said systems were not fully restored and gave no restoration estimate. The deadline suspension ended July 5, and the sheriff’s current Open Records page accepts requests in person, by mail, by email and through an online form. It also says requests are processed in the order received and completed requests are returned by email.
Those current channels support that public-information intake is available again, but they do not establish full restoration, recovery of the requests described as gone or clearance of the reconstruction backlog. DysruptionHub therefore retains a presumed-resolved status rather than treating the incident as authoritatively resolved.
Confidence and uncertainty
Confidence is high that a cyber incident occurred and disrupted records access and processing because the affected organization described the attacks and effects in an official filing. Confidence is also high that staff faced service delays, restricted public access, a backlog and manual reconstruction work.
Confidence is low regarding permanent data loss. The office said some material might never be retrieved, but public evidence does not establish whether records were deleted, encrypted, corrupted or temporarily inaccessible. Ransomware confidence and threat-actor attribution remain unresolved.
Analytic gaps
The public record does not establish the exact dates of the two attacks, the date of initial access, affected infrastructure, compromise method, recovery method or participation by outside incident-response or law-enforcement partners. It also does not resolve whether personal, criminal-justice, evidentiary, jail, employee or public-record data was accessed, altered, destroyed or exfiltrated.
Further official reporting is needed to determine whether all systems were restored after July 5, whether any records remained permanently unrecoverable, whether the backlog was cleared and whether the incident triggered breach notifications or other regulatory reporting.
Organizations involved
Wise County Sheriff's Office

Locations
Organization type
Critical infrastructure
Impacted locations
Sources
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
DysruptionHub reported that hackers twice hit sheriff’s office systems, disrupting records retrieval and request printing, forcing reconstruction of saved requests, and extending deadline suspension through July 5; no ransomware, data theft, actor, or recovery update was identified.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
The sheriff’s office stated that all systems were hit twice by hackers during the week before June 22. Staff could not retrieve records or print incoming requests; logged and saved requests were gone and would need to be rebuilt from sent email files. Systems were not fully restored, no estimate was available and some material might never be retrieved.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
The extension continued the Wise County Sheriff’s Office Public Information Act suspension from June 29 through July 5 and identified it as an extension of the June 22 notice.
- Type: Public Record
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
Wise County’s official page identifies the sheriff’s office as the county government’s public-safety division responsible for law enforcement, emergency response, investigations, and detention, with an address in Decatur, Texas.
- Type: Operational Update
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
The current sheriff’s office Open Records page accepts public-information requests in person, by mail, by email and through an online form. It says requests are processed in the order received and completed requests are returned by email. The page does not state whether systems were fully restored or missing requests recovered.