Millcreek Township
Incident posture
Linked entities
- Victim
- Millcreek Township
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
Unknown actors attempted to infiltrate the municipal computer network and install malicious software, prompting immediate containment actions to block the intrusion. Proactive security systems detected and stopped the attack before any damage occurred, and IT staff, in partnership with VNET, temporarily isolated the network from the internet to conduct a thorough system audit. All Township services continued operating throughout the lockdown, with full functionality restored later that same day. Officials confirmed that no data was compromised and no systems were impacted, while additional security measures were implemented to prevent similar threats in the future.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Sunday, July 13, 2025, Millcreek Township experienced a cybersecurity incident in which unknown actors attempted to infiltrate the Township's computer network and install malicious software. According to the Millcreek Township Police Department, the attempt was detected and blocked by the Township's existing security protocols before any damage, data compromise, or service disruption occurred. The intrusion attempt targeted the Township's core network infrastructure, but because the malicious activity was identified proactively, the attackers were unable to establish a foothold or deploy their payload within the system.
In response to the detected threat, Township IT staff, working in partnership with the Township's technology provider VNET, took immediate precautionary action by temporarily disconnecting the network from the internet. This isolation measure was implemented to prevent any potential further intrusion attempts while a thorough system audit was conducted across the environment. The audit was performed the same day as the incident, and all systems were confirmed to be fully operational again later that same day, allowing Township services to resume normal operation without any prolonged interruption. Throughout the brief network lockdown, all Township services continued to operate, indicating that critical public-facing functions were either maintained through offline processes or otherwise remained available to residents during the response window.
Township officials confirmed following the audit that there was no data breach and no system compromise resulting from the attempted intrusion. The malicious software that the unknown actors had attempted to install was blocked prior to execution or deployment, and no resident or operational data was accessed, exfiltrated, or otherwise affected by the attack. Despite the unsuccessful nature of the intrusion, the Township implemented additional security measures following the incident to reduce the likelihood of similar threats succeeding in the future. Both the Police Department and Township leadership emphasized that the rapid detection and response were the direct result of the proactive security systems and protocols already in place at the time of the attack.
The Millcreek Township Police Department publicly reported the incident, and the Township issued a formal notice to residents and the broader community on July 14, 2025, reassuring the public that services had remained uninterrupted and that no personal or municipal data had been compromised. Officials encouraged residents and other local governments to remain vigilant against cyber threats and to prioritize cybersecurity readiness. The response to the incident demonstrated coordinated action between internal IT personnel, the Township's external technology partner VNET, and law enforcement, all working within the same day to identify the threat, isolate the network, audit the systems, and restore full functionality without any reported impact to Township operations or resident services.
Sources
Sources available to members: 2 sources.