Lancaster, Ohio, took municipal computers offline Aug. 6 after ransomware notifications appeared on multiple employee machines, prompting warnings of possible delays in card payments and other computer-based work.
The city remained operational during the shutdown. An alert reproduced in matching Reddit posts said 911, water, wastewater and telephone systems were not directly affected.

The alert said the city’s information technology department first received a ransomware notification on one computer, followed by additional notices as employees began using their machines. Outside experts advised Lancaster to take all personal computers offline while it investigated and worked to contain the possible threat.
Official city records later confirmed the incident as ransomware. An Aug. 28 committee agenda listed a ransomware update. Minutes from the meeting said Mark Starr of the city’s information technology department reported that about 90% of data and programs had been recovered.
Employees were still working on the remaining 10% three weeks after the initial alerts. The minutes said some of the remaining data or programs might not be restored because of security concerns and that the city was working with its cyber insurance provider on additional safeguards.
According to the minutes, Lancaster already used SentinelOne security software and was considering other endpoint detection and response software as an additional layer of protection. Officials said the project team’s evaluations could lead to further safeguards.
Lancaster has not said whether personal, financial, employee or resident information was accessed or copied. Officials also have not identified an initial access method, ransom demand, payment, malware family or responsible actor.
Lancaster, the Fairfield County seat about 30 miles southeast of Columbus, had an estimated population of 41,956 in 2025, according to the U.S. Census Bureau.
The incident followed a separate ransomware disclosure by Circleville, Ohio that same month. Circleville said it had restored affected municipal systems and paid no ransom but did not identify when its incident began or which public services were affected.
As of Tuesday, Lancaster had not posted a later recovery update in its public notices or meeting records. The Aug. 28 committee minutes remained the latest documented status, with recovery unfinished and some data or programs potentially unrestored for security reasons. The city did not respond to questions by publication time.