Skip to content
RansomwareOngoing

Pennsylvania Office of Attorney General ransomware attack

A ransomware attack knocked the Pennsylvania Office of Attorney General's website, email and phone systems offline for weeks, disrupting court cases; the Inc extortion group later claimed responsibility and the office confirmed a data breach without paying a ransom.

Victim
Pennsylvania Office of Attorney General

On 11 August 2026, the Pennsylvania Office of Attorney General (OAG) disclosed that its entire network was down — including its website, email and main phone line — in what would prove to be a ransomware attack causing a weeks-long outage across offices statewide. The disruption delayed court cases and cut off routine public contact with the Commonwealth's top law-enforcement agency.

What happened

The OAG first announced the outage via social media on 11 August, initially describing a network-wide disruption without confirming a cause. Recovery was slow: website access was partially restored around 14 August, and on 18 August Attorney General Dave Sunday said staff were gradually regaining access to email, with phone lines still down.

On 29 August, Sunday confirmed that the incident involved the deployment of file-encrypting ransomware, and that the office had not paid a ransom. He declined to name the group, citing the ongoing investigation. The Inc extortion group — known for targeting healthcare, education and government entities — claimed responsibility by posting sample documents it said were stolen from the OAG on its data-leak site. Cybersecurity firm Comparitech reported that Inc claimed to have stolen roughly 5.7 terabytes of data from the agency.

Impact

  • A weeks-long outage of the OAG's website, email and phone systems, disrupting operations across Commonwealth offices and delaying court proceedings.
  • The office confirmed a data breach following the ransomware deployment; the full scope of stolen data was still being assessed.
  • The OAG refused to pay the ransom and worked to rebuild systems from backups.

Why it matters

The attack shows how a ransomware intrusion at a single government agency can degrade the machinery of justice itself — delaying cases and severing the public's ability to reach prosecutors. The OAG's decision not to pay aligns with law-enforcement guidance but came at the cost of a prolonged, visible recovery, illustrating the operational price of resilience. The involvement of Inc, an established double-extortion operation, reflects the continued targeting of state and local government entities that hold sensitive investigative and personal data yet often run on constrained security budgets.

Timeline

  1. The Pennsylvania Office of Attorney General discloses via social media that its entire network is down, including its website, email and main phone line.

  2. Website access is partially restored.

  3. Attorney General Dave Sunday announces that employees are gradually regaining access to email; phone lines remain down.

  4. Sunday confirms file-encrypting ransomware was used and that no ransom was paid; the Inc extortion group posts sample documents on its leak site claiming responsibility.

Sources

  1. securityweek.comhttps://www.securityweek.com/pennsylvania-attorney-general-confirms-ransomware-behind-weeks-long-outage/
  2. securityweek.comhttps://www.securityweek.com/pennsylvania-attorney-general-confirms-data-breach-after-ransomware-attack/
  3. therecord.mediahttps://therecord.media/pennsylvania-attorney-general-office-ransomware-attack-recovery
  4. infosecurity-magazine.comhttps://www.infosecurity-magazine.com/news/ransomware-pennsylvania-ag/

Related incidents