Analyst assessment
DysruptionHub assesses with high confidence that Woodhaven Lakes experienced ransomware beginning Aug. 6, 2026. In an official disclosure, the recreational property owners association said ransomware began encrypting Microsoft Office files and documents on on-premises storage before the activity was detected and stopped within hours.
Woodhaven Lakes said affected files were backed up off-site and that it was working with its cyber insurer on investigation, remediation and recovery. The public record does not identify the initial access vector.
Play later listed Woodhaven Association on its leak site and claimed it stole internal data. The listing threatened a full leak unless an organization representative contacted the group. The claim is consistent with the already confirmed ransomware incident, but Woodhaven Lakes has not verified Play, data theft or possession of authentic internal files.
Operational significance
The incident disrupted normal phones and internet, payment processing, office activity and facility operations. Initial notices documented cash-only service, a closed Service Center and an alternate Public Safety contact number. The General Store later restored card payments, but recovery remained uneven across the property.
An Aug. 12 network update said servers and internet were still offline. The association office was open but lacked internet and could not accept payments; the Rec Plex and Tackle Box were cash-only; the Service Center was closed; and the laundromat reopened after an afternoon update. Those conditions show partial facility recovery alongside continuing network-dependent disruption.
Disclosure posture
Woodhaven Lakes first described a phone and internet outage Aug. 6 and supplied operational workarounds without naming a cause. It confirmed ransomware, file encryption, backup availability and the initial data-scope assessment Aug. 7. That organization-first cyber disclosure supports OC, and the Play claim posted Aug. 17 does not change the sequence.
Current status
The incident is presumed resolved. The last documented service workaround was Aug. 12, when servers and internet remained offline and some facilities had payment or access limitations. The current Woodhaven Lakes website again presented ordinary facility, member and payment information when reviewed Aug. 31, and no later outage notice or service complaint was found during the resort’s operating season. This is an analytic presumption based on the return of ordinary public-facing service information and 19 days without contrary operational evidence, not an association-issued incident-wide all-clear. Play’s later extortion claim does not extend the operational-impact period.
Confidence and uncertainty
Confidence is high that ransomware encrypted locally stored files and disrupted operations because Woodhaven Lakes directly confirmed both. The association said its property-owner database and information were unaffected, but that statement does not establish whether other encrypted files were viewed or copied.
Play attribution and the claimed internal-data theft are assessed with low confidence. The stable leak-site listing identifies the claimant, victim and domain and makes a specific extortion claim, but the association, law enforcement and independent technical evidence have not corroborated the actor or theft.
Analytic gaps
The public record does not identify the compromised account or device, access vector, vulnerability, attacker dwell time, persistence, verified exfiltration, demand amount, negotiation, payment, complete affected-system inventory, final restoration time or forensic conclusion. It also does not establish the contents, volume or authenticity of data claimed by Play.