CMI Management
Incident posture
Linked entities
- Victim
- CMI Management
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Southold Town's Laserfiche online records portal was compromised in a cyberattack, causing it to be offline for an extended period before being restored, though users continue to experience slowdowns. Officials noted improvements to isolate the system from internal networks and reported that federal and county agencies assisted in the response, with no suspect publicly identified.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On the day before Thanksgiving in 2025, Southold Town’s Laserfiche online records portal was taken offline by a cybersecurity attack. The breach forced the town’s police department to write reports by hand while efforts were made to restore computer systems. By December 9, 2025, nearly all of the town’s systems had been brought back online, though the portal itself remained unavailable. Federal agencies including the FBI and the Department of Homeland Security, along with Suffolk County officials, responded to the incident. No suspect has been publicly identified in connection with the attack.
The portal remained down for nearly seven months before officials announced its return on June 17, 2026, at a Town Board work session. Upon restoration, some users reported severe slowdowns when trying to access the system, a phenomenon noted by Town Board member Brian Mealy. Board member Tomaszewski said he had not personally experienced issues but suggested the delays could stem from heavy traffic as many community members attempted to log in simultaneously. He urged the public to be patient while the system stabilized. Southold network specialist Liam Chiello observed that, prior to the breach, Laserfiche was not as isolated from the town’s internal networks as desired.
Chiello explained that, after the attack, the town had re‑configured the environment so that Laserfiche is now much more isolated from internal systems and computers, describing the new setup as ‘a lot safer.’ The cybersecurity improvements have been underway since the November 2025 attack, according to Chiello’s update. Officials emphasized that while the portal is back online, a few kinks remain to be worked out. They continue to monitor performance and address any lingering issues as they arise.
Sources
Sources available to members: 1 source.