CSIDB logo
Incident

Prince George County, VA

Incident posture

Attack window
Jun 2026
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-09-10 01:33

Linked entities

Victim
Prince George County, VA
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Jun 2026
Disclosed
Jun 2026
Resolved
Jun 2026

Summary

Prince George County disclosed a cybersecurity attack discovered after staff noticed disruptions to county computer systems. Officials said the nature of the incident made it possible that personal information belonging to residents and county employees was accessed, including names, addresses, dates of birth, driver’s license numbers and Social Security numbers. The county said it acted to stop the incident, engaged outside cybersecurity experts, and notified state and federal law enforcement, including the FBI’s Cyber Crimes Division, as well as CISA. Critical public safety services were not disrupted, systems have been secured, operations have returned to normal, and complimentary credit monitoring is being offered.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Prince George County, Virginia, disclosed that it had been the victim of a cybersecurity attack affecting county computer systems and potentially exposing personal information belonging to citizens and county employees. The incident came to light on or about June 11, when members of the county technology team found disruptions in the county’s computer systems. According to the county press release reported on June 25, 2026, the attack may have allowed perpetrators to access personal information. The county identified several categories of information that were at risk, including names, addresses, dates of birth, driver’s license numbers, and Social Security numbers. The disclosure stated that numerous citizens and county employees may have been exposed. The county said the attack did not disrupt the county’s provision of critical public safety services. It also stated that all county systems were currently secure and that operations had returned to normal.

After discovering the disruptions, county officials said they immediately took steps to stop the incident. The county engaged outside cybersecurity experts to assist with the response and investigate the incident. County officials also contacted state and federal law enforcement. The county specifically said it had contacted the FBI’s Cyber Crimes Division. The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency was also notified. As part of the public response, Prince George County said it was offering complimentary credit monitoring to anyone who wanted to enroll. The credit monitoring was offered in connection with the possible exposure of personal information, including sensitive identifiers such as driver’s license numbers and Social Security numbers.

The county said new cybersecurity safeguards had been put in place following the incident. County officials also said they were evaluating additional actions to strengthen network security. The disclosed impacts involved possible unauthorized access to personal information rather than interruption of critical public safety services. The reported account did not identify the attacker, describe the method used in the attack, or provide a final number of affected individuals. It also did not identify specific county systems beyond the county’s computer systems. The known sequence consisted of disruptions being found on or about June 11, the county taking steps to stop the incident, outside cybersecurity experts being engaged, law enforcement and federal cyber authorities being notified, systems being secured, operations returning to normal, credit monitoring being offered, and additional safeguards being implemented or evaluated.

Sources

Sources available to members: 1 source.

CSIDB