CSIDB logo
Incident

Millcreek Township

Incident posture

Attack window
Jul 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 10:31

Linked entities

Victim
Millcreek Township
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jul 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Unknown actors attempted to infiltrate the municipal computer network and install malicious software, prompting immediate containment actions to block the intrusion. Proactive security systems detected and stopped the attack before any damage occurred, and IT staff, in partnership with VNET, temporarily isolated the network from the internet to conduct a thorough system audit. All Township services continued operating throughout the lockdown, with full functionality restored later that same day. Officials confirmed that no data was compromised and no systems were impacted, while additional security measures were implemented to prevent similar threats in the future.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On Sunday, July 13, 2025, Millcreek Township experienced a cybersecurity incident in which unknown actors attempted to infiltrate the Township's computer network and install malicious software. According to the Millcreek Township Police Department, the attempt was detected and blocked by the Township's existing security protocols before any damage, data compromise, or service disruption occurred. The intrusion attempt targeted the Township's core network infrastructure, but because the malicious activity was identified proactively, the attackers were unable to establish a foothold or deploy their payload within the system.

In response to the detected threat, Township IT staff, working in partnership with the Township's technology provider VNET, took immediate precautionary action by temporarily disconnecting the network from the internet. This isolation measure was implemented to prevent any potential further intrusion attempts while a thorough system audit was conducted across the environment. The audit was performed the same day as the incident, and all systems were confirmed to be fully operational again later that same day, allowing Township services to resume normal operation without any prolonged interruption. Throughout the brief network lockdown, all Township services continued to operate, indicating that critical public-facing functions were either maintained through offline processes or otherwise remained available to residents during the response window.

Township officials confirmed following the audit that there was no data breach and no system compromise resulting from the attempted intrusion. The malicious software that the unknown actors had attempted to install was blocked prior to execution or deployment, and no resident or operational data was accessed, exfiltrated, or otherwise affected by the attack. Despite the unsuccessful nature of the intrusion, the Township implemented additional security measures following the incident to reduce the likelihood of similar threats succeeding in the future. Both the Police Department and Township leadership emphasized that the rapid detection and response were the direct result of the proactive security systems and protocols already in place at the time of the attack.

The Millcreek Township Police Department publicly reported the incident, and the Township issued a formal notice to residents and the broader community on July 14, 2025, reassuring the public that services had remained uninterrupted and that no personal or municipal data had been compromised. Officials encouraged residents and other local governments to remain vigilant against cyber threats and to prioritize cybersecurity readiness. The response to the incident demonstrated coordinated action between internal IT personnel, the Township's external technology partner VNET, and law enforcement, all working within the same day to identify the threat, isolate the network, audit the systems, and restore full functionality without any reported impact to Township operations or resident services.

Sources

Sources available to members: 2 sources.

CSIDB