CSIDB logo
Incident

Delaware County

Incident posture

Attack window
Jun 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-22 12:23

Linked entities

Victim
Delaware County
Threat actors
0 actors
Sources
3 sources

Timeline

Occurred
Jun 2026
Discovered
Jun 2026
Disclosed
Jul 2026
Resolved
Pending

Summary

Delaware County experienced a cyberattack that forced a shutdown of its government systems, disrupting phones, networks and several online services. Staff responded by isolating the network and continuing operations with paper‑based processes while working with cybersecurity specialists and forensic counsel to investigate the intrusion. Restoration efforts have brought back most functions, including payroll and vendor payments, though the library search system and some recorder and wills offices remain partially unavailable. The county has not disclosed whether a ransom was paid and is using its cyberinsurance to cover costs, while continuing to assess any potential exposure of sensitive data and preparing required notifications if needed.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On June 26, Delaware County staff detected unauthorized activity on the government network and immediately shut down systems, which disrupted phone service and network operations across county departments. The shutdown initiated a two‑and‑a‑half‑week period during which the county worked to restore services while continuing to serve the public through paper‑based processes where necessary. County Executive Director Barbara O’Malley stated that the disruption was part of a sophisticated cybercriminal attack that allowed attackers to gain access to the county’s network, and that the investigation was being conducted with the assistance of cybersecurity specialists to determine the full scope and any risk to county data. When asked about a possible ransom payment, O’Malley said she could not share details until the investigation concluded, noting that the county was working through its cyberinsurance coverage. She emphasized that a primary focus of the assessment was identifying whether any sensitive data had been accessed without authorization and that the county would issue legally required notifications if such access were confirmed. The investigation also aimed to establish how many and which specific county departments were affected by the intrusion. O’Malley confirmed that no further unauthorized activity had been observed since the containment measures were put in place on June 26, and that the county had implemented additional network safeguards while reviewing existing policies and procedures. Despite the outage, the county reported that payroll for employees continued to be processed and payments to vendors were being made, although certain services such as the library search system and some functions in the Recorder of Deeds and Register of Wills offices remained inaccessible as of the July 16 update. Online title searches, which were unavailable at the onset of the incident, had been restored by that time, while electronic title searches remained unavailable for a period; paper records stayed accessible to the public throughout. The Register of Wills and Recorder of Deeds offices were working to enter manually collected information into their computer systems to catch up on backlogs.

In response to the incident, the county engaged third‑party cybersecurity counsel and forensic specialists to assist with the investigation and recovery efforts, and reported that its teams had restored nearly all county operations. Public inquiries were directed to the email address [email protected] or the phone number 610‑891‑4943 for assistance accessing services. During a subsequent council meeting, resident Carris Kocher requested greater transparency and submitted a 166‑question request for information about the attack, emphasizing the need to know whether personal data had been protected and what lessons would be learned. Council Vice Chair Christine Reuther noted that the county’s cybersecurity posture had been strengthened by lessons from a 2020 incident, which had mitigated the impact of the current attack. Joy Schwartz of Drexel Hill asked for details on the financial cost to taxpayers, any planned corrective investments, and the county’s long‑term cyberstrategy. Greg Stenstorm of Glen Mills inquired whether election systems had been compromised and if additional verification measures would be instituted for future elections. Scott Thomas of Marple sought clarification on whether any county records had been compromised and whether affected data or systems had been fully restored from backups. Council Member Joanne Phillips affirmed that the county was doing its best to address the situation and balance public interest with procedural constraints. The Delaware County GOP issued statements on its Facebook page calling for transparency and supporting a referendum to add two seats to the council to increase minority party representation.

Sources

Sources available to members: 3 sources.

CSIDB