Skip to content

Woodhaven Lakes ransomware incident

Summary

Woodhaven Lakes logo

Woodhaven Lakes last documented server, internet and facility workarounds August 12. Ordinary facility, member and payment information was available by August 31 with no later outage report, supporting presumed resolution while Play’s claim remains unverified.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Data encryption

    Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internet access disruption

    The organization lost or materially restricted internet connectivity.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Payment processing disruption

    The organization could not process, receive, issue, reconcile, or record payments normally.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Emergency communications disruption

    Emergency notification, public warning, radio, alerting, 911, or emergency coordination communications were unavailable or impaired.

  • Facility closure

    One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Woodhaven Lakes experienced ransomware beginning Aug. 6, 2026. In an official disclosure, the recreational property owners association said ransomware began encrypting Microsoft Office files and documents on on-premises storage before the activity was detected and stopped within hours.

Woodhaven Lakes said affected files were backed up off-site and that it was working with its cyber insurer on investigation, remediation and recovery. The public record does not identify the initial access vector.

Play later listed Woodhaven Association on its leak site and claimed it stole internal data. The listing threatened a full leak unless an organization representative contacted the group. The claim is consistent with the already confirmed ransomware incident, but Woodhaven Lakes has not verified Play, data theft or possession of authentic internal files.

Operational significance

The incident disrupted normal phones and internet, payment processing, office activity and facility operations. Initial notices documented cash-only service, a closed Service Center and an alternate Public Safety contact number. The General Store later restored card payments, but recovery remained uneven across the property.

An Aug. 12 network update said servers and internet were still offline. The association office was open but lacked internet and could not accept payments; the Rec Plex and Tackle Box were cash-only; the Service Center was closed; and the laundromat reopened after an afternoon update. Those conditions show partial facility recovery alongside continuing network-dependent disruption.

Disclosure posture

Woodhaven Lakes first described a phone and internet outage Aug. 6 and supplied operational workarounds without naming a cause. It confirmed ransomware, file encryption, backup availability and the initial data-scope assessment Aug. 7. That organization-first cyber disclosure supports OC, and the Play claim posted Aug. 17 does not change the sequence.

Current status

The incident is presumed resolved. The last documented service workaround was Aug. 12, when servers and internet remained offline and some facilities had payment or access limitations. The current Woodhaven Lakes website again presented ordinary facility, member and payment information when reviewed Aug. 31, and no later outage notice or service complaint was found during the resort’s operating season. This is an analytic presumption based on the return of ordinary public-facing service information and 19 days without contrary operational evidence, not an association-issued incident-wide all-clear. Play’s later extortion claim does not extend the operational-impact period.

Confidence and uncertainty

Confidence is high that ransomware encrypted locally stored files and disrupted operations because Woodhaven Lakes directly confirmed both. The association said its property-owner database and information were unaffected, but that statement does not establish whether other encrypted files were viewed or copied.

Play attribution and the claimed internal-data theft are assessed with low confidence. The stable leak-site listing identifies the claimant, victim and domain and makes a specific extortion claim, but the association, law enforcement and independent technical evidence have not corroborated the actor or theft.

Analytic gaps

The public record does not identify the compromised account or device, access vector, vulnerability, attacker dwell time, persistence, verified exfiltration, demand amount, negotiation, payment, complete affected-system inventory, final restoration time or forensic conclusion. It also does not establish the contents, volume or authenticity of data claimed by Play.

Threat actor and claim

Listed as: Woodhaven AssociationSource: ransomware.livePublished: Discovered:

Claim details

Play listed Woodhaven Association and woodhavenassociation.com on August 17 and claimed it stole internal data. The listing threatened to publish a full leak unless an organization representative contacted the group. Woodhaven Lakes had already confirmed ransomware and file encryption, but it has not confirmed Play attribution, data theft, possession of authentic files, a leak, direct contact, a ransom amount or payment activity.

Organizations involved

Impacted location

Sources

Ransomware disrupts Woodhaven Lakes services in Illinois

We reported that ransomware encrypted locally stored Microsoft Office files and documents, disrupted phones and internet, limited payments and closed facilities. Card payments and food service returned at the General Store by August 8, but the Service Center remained closed through August 9 and Woodhaven Lakes had not announced a broader restoration.

Woodhaven Lakes alternate Public Safety contact notice

Woodhaven Lakes said its phone systems were down and directed anyone with an emergency to call the organization’s Public Safety cell phone instead.

Woodhaven Lakes phone and internet outage notice

Woodhaven Lakes said it was experiencing a phone and internet outage. The Service Center was closed, and the General Store and RecPlex could accept only cash at that time.

Woodhaven Lakes ransomware and recovery update

Woodhaven Lakes said ransomware began encrypting locally stored Microsoft Office files and documents on on-premises storage devices before being stopped within hours. It reported no breach of the Property Owner database, said affected files were backed up offsite and documented continuing phone, payment, Service Center and cash-only operational restrictions.

Woodhaven Lakes victim of ransomware attack Thursday

WLPO reported that Woodhaven Lakes stopped a ransomware attack that encrypted files on local storage. The report said phones remained down, in-office assessment payments were unavailable, the RecPlex accepted only cash and services were being restored cautiously while the Property Owner database was reported unaffected.

Woody's General Store reopens with card payments

Woodhaven Lakes shared the General Store’s update that it had reopened and was accepting cash and credit-card payments, with food service beginning at 11 a.m.

Woody's Service Center closure during network maintenance

Woodhaven Lakes shared Woody’s Service Center’s notice that ongoing network maintenance required the facility to close for the remainder of August 8 and all of Sunday, August 9. The facility hoped to resume operations Monday morning but did not announce a confirmed reopening.

Woodhaven Lakes network update

Woodhaven Lakes said Aug. 12 that servers and internet remained offline. The association office could not accept payments, the Rec Plex and Tackle Box were cash-only, and the Service Center was closed. An afternoon edit said the laundromat had returned to service.

Woodhaven Association — claimed by Play

A ransomware.live record preserves Play’s August 17 listing of Woodhaven Association and woodhavenassociation.com. Play claimed it stole internal data and threatened to publish a full leak unless an organization representative contacted the group. The listing does not authenticate any alleged data or establish Play’s responsibility.

Woodhaven Lakes official website

As reviewed Aug. 31, the association website presented ordinary facility, member and payment information and did not display a continuing cyber-related outage warning or service workaround.

See something that needs correction?

Signed-in members can report an error, update, or missing source.