Skip to content

Ransomware forces Lancaster, Ohio, to take city computers offline

Card payments and other computer work were delayed, while 911, water, wastewater and phone systems were not directly affected.

Stone arch framing glass double doors beneath a window reading “Municipal Building 104” at Lancaster City Hall.
The entrance to Lancaster City Hall at 104 E. Main St. in Lancaster, Ohio. (City of Lancaster)

Lancaster, Ohio, took municipal computers offline Aug. 6 after ransomware notifications appeared on multiple employee machines, prompting warnings of possible delays in card payments and other computer-based work.

The city remained operational during the shutdown. An alert reproduced in matching Reddit posts said 911, water, wastewater and telephone systems were not directly affected.

Screenshot of a Reddit post reproducing Lancaster’s Aug. 6 ransomware alert about computers being taken offline and possible payment-processing delays.
A Reddit user reposted Lancaster’s Aug. 6, 2026, alert announcing ransomware notifications and the precautionary shutdown of city computers. (Screenshot via Reddit)

The alert said the city’s information technology department first received a ransomware notification on one computer, followed by additional notices as employees began using their machines. Outside experts advised Lancaster to take all personal computers offline while it investigated and worked to contain the possible threat.

Official city records later confirmed the incident as ransomware. An Aug. 28 committee agenda listed a ransomware update. Minutes from the meeting said Mark Starr of the city’s information technology department reported that about 90% of data and programs had been recovered.

Employees were still working on the remaining 10% three weeks after the initial alerts. The minutes said some of the remaining data or programs might not be restored because of security concerns and that the city was working with its cyber insurance provider on additional safeguards.

According to the minutes, Lancaster already used SentinelOne security software and was considering other endpoint detection and response software as an additional layer of protection. Officials said the project team’s evaluations could lead to further safeguards.

Lancaster has not said whether personal, financial, employee or resident information was accessed or copied. Officials also have not identified an initial access method, ransom demand, payment, malware family or responsible actor.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

Lancaster, the Fairfield County seat about 30 miles southeast of Columbus, had an estimated population of 41,956 in 2025, according to the U.S. Census Bureau.

The incident followed a separate ransomware disclosure by Circleville, Ohio that same month. Circleville said it had restored affected municipal systems and paid no ransom but did not identify when its incident began or which public services were affected.

As of Tuesday, Lancaster had not posted a later recovery update in its public notices or meeting records. The Aug. 28 committee minutes remained the latest documented status, with recovery unfinished and some data or programs potentially unrestored for security reasons. The city did not respond to questions by publication time.

Joseph Topping

Joseph Topping

Joseph Topping is the founder and editor of DysruptionHub, reporting on cyber incidents and technology failures that disrupt public services, organizations and daily life.

All articles

More in Government

See all

More from Joseph Topping

See all