Skip to content

Wise County Sheriff’s Office cyberattack disrupts records access

Summary

The Wise County Sheriff’s Office said hackers hit its systems twice during the week before June 22, 2026, preventing records retrieval and printing of incoming public-information requests. Logged and saved requests were lost or inaccessible and had to be rebuilt from sent email files. The deadline suspension ended July 5 and official request channels are currently available, but full restoration and recovery of missing requests remain unconfirmed.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

Incident confidence:
High
Ransomware:
Unresolved

DD-CIT classification

OC-ODOfficial cyberOfficial disruptionAbout the DD-CIT methodology

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Backlog created

    The disruption caused an accumulation of unprocessed requests, cases, orders, records, appointments, or other work.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that the Wise County Sheriff’s Office experienced malicious cyber activity that materially disrupted records operations in June 2026. In a June 22 catastrophe notice, the office said all systems had been hit twice by hackers during the preceding week. Staff could not retrieve records or print incoming public-information requests, and logged and saved requests were gone or inaccessible.

The filing narrows both attacks only to the week before June 22; it does not identify either attack date. The evidence confirms malicious cyber activity but not its mechanism. No public source identifies initial access, a compromised account, an exploited vulnerability, malware, encryption, data exfiltration or a responsible threat actor. No ransomware confirmation or ransom demand was found.

Operational significance

The disruption directly affected compliance with the Texas Public Information Act. The office said requests would have to be rebuilt from fulfilled-request records retained in sent email files, indicating loss of normal records access, delayed processing and a manual reconstruction burden. It warned that some missing material might never be retrieved.

The sheriff’s office suspended public-information deadlines from June 22 through June 28. A second catastrophe notice extended the suspension through July 5, showing that the operational effect continued beyond the initial period. The current Texas attorney general register contains no later Wise County Sheriff’s Office extension.

The confirmed impact is administrative and records-related. The public record does not establish whether 911, dispatch, patrol, detention, communications, evidence management or other public-safety functions were disrupted. Those effects cannot be inferred from the broader statement that all systems were hit.

Disclosure posture

The clearest disclosure came through notices filed with the Texas attorney general rather than a detailed public-facing incident update. DysruptionHub’s published report documented the notices, the extension through July 5 and the absence of public answers about ransomware, data theft, attribution and public-safety effects.

The notices acknowledge malicious activity and operational disruption but provide little technical or recovery detail. No later breach notice, affected-data disclosure or forensic conclusion was found. That absence does not establish that no data was accessed; confidentiality and integrity effects remain unresolved.

Current status

The June 22 notice said systems were not fully restored and gave no restoration estimate. The deadline suspension ended July 5, and the sheriff’s current Open Records page accepts requests in person, by mail, by email and through an online form. It also says requests are processed in the order received and completed requests are returned by email.

Those current channels support that public-information intake is available again, but they do not establish full restoration, recovery of the requests described as gone or clearance of the reconstruction backlog. DysruptionHub therefore retains a presumed-resolved status rather than treating the incident as authoritatively resolved.

Confidence and uncertainty

Confidence is high that a cyber incident occurred and disrupted records access and processing because the affected organization described the attacks and effects in an official filing. Confidence is also high that staff faced service delays, restricted public access, a backlog and manual reconstruction work.

Confidence is low regarding permanent data loss. The office said some material might never be retrieved, but public evidence does not establish whether records were deleted, encrypted, corrupted or temporarily inaccessible. Ransomware confidence and threat-actor attribution remain unresolved.

Analytic gaps

The public record does not establish the exact dates of the two attacks, the date of initial access, affected infrastructure, compromise method, recovery method or participation by outside incident-response or law-enforcement partners. It also does not resolve whether personal, criminal-justice, evidentiary, jail, employee or public-record data was accessed, altered, destroyed or exfiltrated.

Further official reporting is needed to determine whether all systems were restored after July 5, whether any records remained permanently unrecoverable, whether the backlog was cleared and whether the incident triggered breach notifications or other regulatory reporting.

Organizations involved

Impacted locations

Sources

Wise County Sheriff’s Office hack disrupts Texas records access
DysruptionHubBy DysruptionHub StaffPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

DysruptionHub reported that hackers twice hit sheriff’s office systems, disrupting records retrieval and request printing, forcing reconstruction of saved requests, and extending deadline suspension through July 5; no ransomware, data theft, actor, or recovery update was identified.

Wise County Sheriff's Office Catastrophe Notice
Office of the Attorney General of TexasPublished: Retrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

The sheriff’s office stated that all systems were hit twice by hackers during the week before June 22. Staff could not retrieve records or print incoming requests; logged and saved requests were gone and would need to be rebuilt from sent email files. Systems were not fully restored, no estimate was available and some material might never be retrieved.

Wise County Sheriff's Office Catastrophe Notice Extension
Office of the Attorney General of TexasPublished: Retrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

The extension continued the Wise County Sheriff’s Office Public Information Act suspension from June 29 through July 5 and identified it as an extension of the June 22 notice.

Sheriff
Wise County, TexasRetrieved:
  • Type: Public Record
  • Stance: Confirm
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

Wise County’s official page identifies the sheriff’s office as the county government’s public-safety division responsible for law enforcement, emergency response, investigations, and detention, with an address in Decatur, Texas.

Open Records
Wise County Sheriff's OfficeRetrieved:
  • Type: Operational Update
  • Stance: Confirm
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

The current sheriff’s office Open Records page accepts public-information requests in person, by mail, by email and through an online form. It says requests are processed in the order received and completed requests are returned by email. The page does not state whether systems were fully restored or missing requests recovered.