US Municipal Cyber Breach Report 2026: Ransomware, Water Utility Attacks, and the State of Local Government Security
A sourced national analysis of cyberattacks on US state and local government: FBI IC3 data, government ransomware counts, recovery costs, and the 2026 water utility attack wave.
This report aggregates what happened to US municipal, county, and state government systems through 2024, 2025, and the first half of 2026. Every incident and figure below is drawn from a federal source (FBI IC3, CISA, EPA, GAO, Treasury), an official government statement, or established reporting, with each claim cited in the Sources section. Where an attribution is claimed by a ransomware group but not confirmed by the victim, we say so.
Executive Summary
Key Findings
- The FBI's Internet Crime Complaint Center logged 1,008,597 complaints in 2025, the first year over one million, with $20.9 billion in reported losses, up 26 percent from 2024.[1]
- Government Facilities was the third most targeted critical infrastructure sector in 2025, with 258 ransomware complaints and 189 data breach complaints reported to the FBI.[1]
- Researchers tracked 117 US government entities hit by ransomware in 2024, up from 95 in 2023, alongside 116 K-12 districts covering 2,275 schools.[2]
- In 2025, the United States accounted for 103 of the 276 government ransomware attacks tracked worldwide through Q3, with an average ransom demand of $1.95 million.[4]
- Ransomware took down an entire state government for the first time: Nevada's August 2025 incident disrupted the DMV, Medicaid, and welfare systems statewide.[6]
- In July 2026, cyberattacks on water utilities in at least 12 states changed passwords on internet-facing controllers, causing pressure loss and flooding; the FBI and EPA issued a joint alert, and Iranian-affiliated actors are the publicly named suspects pending official attribution.[13][14][15]
- Mean ransomware recovery cost for state and local government reached $2.83 million in 2024, more than double the prior year.[16]
- Only 22 percent of state CISOs say their staff has the competencies they need, down from 47 percent in 2024, and 68 percent of state, local, tribal, and territorial organizations lack the budget to address major security priorities.[19][20]
The Headline Numbers: Government in the FBI IC3 2025 Annual Report
National Context
The FBI's 2025 Internet Crime Report, released in April 2026, recorded 1,008,597 complaints and $20.877 billion in reported losses, a 26 percent increase over 2024's $16.6 billion. The average reported loss was $20,699.[1]
Ransomware complaints rose for a third straight year: 3,611 in 2025, up from 3,156 in 2024 and 2,825 in 2023. The FBI notes its $32.3 million ransomware loss figure excludes downtime, remediation, and lost business, and is therefore artificially low. The report identified 63 new ransomware variants and named Akira, Qilin, Play, RansomHub, LockBit, and Medusa among the ten most reported.[1]
The Government Slice
Among critical infrastructure sectors reporting to the FBI, Government Facilities ranked third for ransomware complaints in 2025 with 258, behind Healthcare and Public Health at 460 and Critical Manufacturing at 355, plus another 189 government data breach complaints. The top variants named by the FBI most impacted exactly these three sectors.[1]
One detail from the report is worth every finance director's attention: a city government office in Oregon lost more than $6 million to a business email compromise scheme in April 2025. The FBI's Recovery Asset Team clawed it back, one of the rare wins, but the loss route was an email, not an exploit.[1]
How Many Governments Are Actually Getting Hit
No single tracker sees everything, so this report uses the two most cited independent counts and states their scope precisely.
Emsisoft's US-focused count recorded 117 government entities hit by ransomware in 2024, up from 95 in 2023, alongside 116 K-12 school districts (2,275 schools), 55 colleges and universities, and 85 hospital systems. Emsisoft describes its own counts as undercounts, since many incidents are never disclosed.[2]
Comparitech's worldwide tracking logged 374 ransomware attacks on government entities in 2025, up 27 percent from 294 in 2024, with 2.19 million records affected and an average ransom demand of $1.55 million. Through the first three quarters of 2025, 103 of the 276 tracked government attacks were US-based. The single largest confirmed US government-sector breach in that window was the Pierce County Library System in Washington, at 336,826 people.[3][4]
The first half of 2026 continued the pattern: 187 government attacks tracked worldwide, up 13 percent year over year, with the US accounting for 58. The most active groups against government targets were The Gentlemen, Qilin, and LockBit.[5]
The Incidents That Defined the Window
State of Nevada: The First Statewide Takedown (August 2025)
Nevada's incident began with an employee downloading malicious software around May 2025; the intrusion erupted on August 24, 2025, disrupting the DMV, Medicaid, welfare, and state websites. It is the first ransomware attack to take down an entire US state government. Nevada refused to pay, restored 90 percent of affected data within 28 days, and published an official after-action report. Response costs reached at least $1.5 million, including $1.3 million in contractor support and 4,212 hours of state employee overtime.[6]
St. Paul, Minnesota: The National Guard Deploys (July 2025)
The Interlock ransomware group hit St. Paul on July 25, 2025. The city declared a state of emergency and Minnesota's governor activated the National Guard's cyber unit, the first such activation for a municipal ransomware event. The city refused to pay; Interlock leaked 43 GB of data on August 11, and roughly 3,500 employees reset credentials.[7]
City of Columbus, Ohio (July 2024)
Rhysida's July 18, 2024 attack on Columbus led to breach notifications for 500,000 people. The group claimed 6.5 TB stolen and leaked 3.1 TB after failed negotiations.[8]
Fulton County, Georgia (January 2024)
LockBit's attack took down county phones, court systems, and property tax systems. The county refused two ransom deadlines and no payment was made on its behalf; commissioners later approved a $10.2 million contract for a full systems overhaul. Our Georgia Cybersecurity Breach Report covers the full Georgia picture, including the May 2026 Murray County incident in which a county paid $200,000.[9]
Abilene, Texas (April 2025)
After an April 18, 2025 attack in which Qilin claimed 477 GB of stolen data, Abilene refused to pay and chose instead to replace its network infrastructure, servers, storage, and endpoints outright.[10]
The Pattern in Miniature
Three more 2025 data points sketch the range of outcomes: Cleveland Municipal Court refused a $4 million Qilin demand in February; Gloversville, New York made a rare confirmed payment of $150,000 in March; and Pierce County Library System's breach affected 336,826 people, the largest US government-sector breach through Q3.[3][4]
Our state-level reports document the same pattern county by county: Dallas County's Play ransomware notifications to 201,404 people, the Los Angeles County Superior Court closing all 36 courthouses for days, Patelco Credit Union's two-week outage affecting 726,000 members, and the Florida Department of Health's 729,699-record RansomHub breach, among dozens of others.[21]
Water Utilities on the Front Line: The 2026 Attack Wave
The most consequential municipal cybersecurity story of 2026 is happening at water systems, and it did not come out of nowhere. The escalation traces cleanly through public federal advisories across three years.
2023-2024: CyberAv3ngers and the First Federal Response
Beginning November 22, 2023, actors affiliated with Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command, operating as CyberAv3ngers, compromised Unitronics Vision programmable logic controllers at US water and wastewater facilities that were exposed to the internet with default or missing passwords. The joint CISA, FBI, NSA, EPA, and Israel National Cyber Directorate advisory documents at least 75 compromised devices between November 2023 and January 2024, at least 34 of them in the US water sector. The first publicly known victim was the Municipal Water Authority of Aliquippa, Pennsylvania, where a booster station controller was defaced and the utility switched to manual operations.[11][12]
The federal response escalated quickly: the US Treasury sanctioned six IRGC-CEC officials in February 2024 over the water attacks, calling the deliberate targeting of critical infrastructure "an unconscionable and dangerous act."[22]
The Posture Problem the Government Documented Itself
Federal assessments show why water keeps getting hit. An EPA enforcement alert in May 2024 found that over 70 percent of water systems inspected since September 2023 were in violation of basic Safe Drinking Water Act security requirements, with inspectors finding unchanged default passwords, shared logins, and un-revoked access for former employees.[23] The EPA Inspector General's November 2024 passive assessment of 1,062 drinking water systems serving 193 million people found 97 systems serving roughly 26.6 million people with critical or high-severity vulnerabilities.[24] GAO has issued two reports, in August 2024 and May 2026, documenting that the roughly 170,000 US water and wastewater systems face rising threats while cybersecurity remains voluntary and EPA has identified critical gaps in its own legal authority to require it.[25][26]
2026: Escalation During the Iran Conflict
Following the military conflict between Iran and the United States and Israel that began in early 2026, allied cyber agencies assessed that Iran would very likely use its cyber program against critical infrastructure.[27] In April 2026, the FBI, CISA, NSA, EPA, DOE, US Cyber Command, and Treasury published joint advisory AA26-097A attributing an ongoing PLC exploitation campaign across US water, energy, and government sectors to Iranian-affiliated APT actors, stating the campaigns had escalated in response to the hostilities. The July 22, 2026 update documented actors using legitimate vendor engineering software to modify controller project files in ways that disabled shutdown and alarm logic, letting systems enter unsafe conditions without notifying operators.[13]
Then it became operational. On July 30, 2026, the FBI and EPA issued a joint alert: since July 27, water and wastewater utilities in at least seven states had reported incidents in which actors compromised internet-facing Rockwell Automation MicroLogix 1100 and 1400 controllers, changed device IP addresses and passwords, and caused loss of monitoring and control. Reported operational effects included loss of pressure and flooding, and the alert notes pressure loss can allow untreated groundwater to seep into pipes.[14] By August 4, reporting put the count at water systems in at least 12 states, with Minnesota officials confirming 30 municipal water facilities targeted and Michigan 9. Iran is the publicly named prime suspect; official attribution for the July wave has not been confirmed. No widespread disruption to drinking water has occurred so far, and affected utilities switched to manual operations.[15]
The American Water Works Association wrote to Congressional leadership on August 5, 2026 asking for expanded federal cyber support for utilities of every size, noting that water utilities are "often out of sight and out of mind."[28] There is still no mandatory federal cybersecurity standard for water system operational technology.[26]
What Water Utilities and the Cities That Run Them Should Do Now
The federal guidance across all of these advisories is consistent and unglamorous: get PLCs and HMIs off the public internet, change every default password, put multifactor authentication on remote access, take a current inventory of internet-facing devices, and rehearse manual operations. Every incident above involved internet-exposed controllers with weak or default credentials. Utilities that need structured help stress-testing this posture can start with a free cybersecurity assessment or bring in virtual CISO services scoped for critical infrastructure operators.
State by State: Where the Losses Concentrate
The FBI's 2025 state tables show internet crime losses concentrating in the large-economy states. The top ten by reported losses: California ($3.67 billion), Texas ($1.83 billion), Florida ($1.60 billion), New York ($1.23 billion), New Jersey ($660 million), Arizona ($631 million), Pennsylvania ($538 million), Illinois ($535 million), Georgia ($535 million), and Virginia ($476 million). Washington ranked 11th at $458 million.[1]
BlueRadius publishes sourced state-level breach reports that go beneath these totals to the county and municipal incidents behind them:
- California: the #1 state by complaints and losses; courts, housing authorities, and school districts in the blast radius.
- Texas: #2 by losses; county governments, appraisal districts, and city utilities under sustained ransomware pressure.
- Florida: #3 by losses; home to the 729,699-record Florida Department of Health breach.
- New York: crossed $1 billion in annual losses for the first time in 2025; Suffolk County's recovery passed $25 million.
- Illinois: rose to #5 nationally in complaints; state agencies exposed data on more than 1.8 million residents across two incidents.
- Georgia: entered the top 10 in both complaints and losses; the refusal-to-pay norm broke in May 2026 when Murray County paid $200,000.
- Washington: 11.6 million breach notices in a single year, more than the state's population.
What a Government Breach Costs
Sophos's sector survey found 34 percent of state and local government organizations were hit by ransomware in 2024, down sharply from 69 percent in 2023, but the attacks that landed were worse: 98 percent resulted in data encryption, mean recovery costs reached $2.83 million (more than double 2023's $1.21 million), and among organizations that paid, the median payment was $2.2 million, with only 20 percent paying the initial demand.[16]
IBM's 2025 Cost of a Data Breach study put the public sector's average breach cost at $2.86 million, the lowest of any industry but rising against a falling global average; the US all-industry average hit a record $10.22 million.[17] Comparitech's tracking put the average ransom actually paid by government entities at $923,000 in 2024, against average demands of $1.55 to $1.95 million in 2025.[3][4]
The pattern across Nevada ($1.5 million and counting), Fulton County ($10.2 million overhaul), Suffolk County (more than $25 million), and Atlanta's 2018 attack (roughly $17 million projected) is that recovery costs dwarf the demands, whether or not anyone pays.[6][9][21]
Why It Keeps Happening: The Capacity Gap
The 2026 NASCIO-Deloitte study of state CISOs found only 22 percent reporting budget increases of 6 percent or more, down from 40 percent in 2024, and only 22 percent saying their staff has the required competencies, down from 47 percent.[19] MS-ISAC's August 2025 report found 68 percent of state, local, tribal, and territorial organizations lack the budget to address their major cybersecurity priorities, with small and rural communities disproportionately exposed.[20] CISA's State and Local Cybersecurity Grant Program sets a 70 percent target for entities implementing MFA on remote and privileged access, a target, not a measurement, which says a great deal on its own.[18]
That is the structural story behind every incident in this report: concentrated resident data, lean security programs, aging operational technology, and adversaries ranging from ransomware affiliates to state-aligned APT groups who know all of it.
What This Means for Municipal and Mid-Market Leaders
1. The email and the exposed controller are still the front door. The Oregon BEC loss ($6 million via email) and the water wave (internet-facing PLCs with changed passwords) bracket the problem: most of these incidents did not require sophistication, they required an unlocked door. Identity controls, MFA everywhere, and an inventory of what is internet-facing remove the majority of the attack surface documented above.
2. Refusing to pay works, but only with preparation. Nevada, St. Paul, Fulton County, Cleveland Municipal Court, and Abilene all refused, and all recovered, because backups, manual procedures, and outside help existed. Sophos found 78 percent of government victims restored from backups. Murray County's $200,000 payment shows what the alternative looks like when leverage is gone. Tested backups and a rehearsed incident response plan are what make refusal an option.
3. Security leadership is the gap most entities can actually close. Most municipal and mid-market organizations in these incidents had no dedicated security leader; states themselves report a staffing competency crisis. That leadership layer does not have to be a $250,000 hire. A virtual CISO gives a city, county, utility, or mid-market company an experienced security executive at a fraction of full-time cost, and a fractional CISO engagement can stand up the assessment, the incident response plan, and the board reporting cadence that the entities above lacked. Our board reporting guide covers how to translate this data into governance action.
Frequently Asked Questions
How many US government entities were hit by ransomware in 2024?
Emsisoft counted 117 US government entities hit by ransomware in 2024, up from 95 in 2023, and describes that as an undercount since many incidents go undisclosed. Separately, 116 K-12 districts and 55 colleges and universities were hit.[2]
What happened to US water utilities in July 2026?
Since July 27, 2026, water and wastewater utilities in at least seven states (rising to at least 12 by August 4) reported cyberattacks in which actors compromised internet-facing Rockwell Automation MicroLogix controllers, changed IP addresses and passwords, and caused loss of monitoring and control, with reported effects including pressure loss and flooding. The FBI and EPA issued a joint alert on July 30, 2026. Iranian-affiliated actors are the publicly named suspects; official attribution is pending.[14][15]
Was the 2026 water attack wave connected to Iran?
Federal agencies attribute the broader PLC exploitation campaign that began by March 2026 to Iranian-affiliated APT actors and state that it escalated in response to hostilities between Iran and the United States and Israel. For the specific late-July water incidents, Iran is the publicly reported prime suspect but attribution has not been officially confirmed.[13][15]
What does a municipal ransomware attack cost?
Mean recovery cost for state and local government reached $2.83 million in 2024 per Sophos, and the median payment among those who paid was $2.2 million. Real recoveries run higher: Fulton County approved a $10.2 million overhaul, Suffolk County's recovery exceeded $25 million, and Nevada's statewide incident cost at least $1.5 million with no ransom paid.[16][9][21][6]
Do most government victims pay the ransom?
Sophos found 54 percent of state and local government victims paid in its 2024 survey window, but the highest-profile US incidents of 2024-2026 were refusals: Nevada, St. Paul, Columbus, Fulton County, Cobb County, Cleveland Municipal Court, and Abilene all declined. Confirmed payments are rare in the public record; Gloversville, New York ($150,000) and Murray County, Georgia ($200,000) are two documented exceptions.[16][3][9]
Which states lose the most to cybercrime?
By 2025 FBI IC3 reported losses: California ($3.67B), Texas ($1.83B), Florida ($1.60B), New York ($1.23B), then New Jersey, Arizona, Pennsylvania, Illinois, Georgia, and Virginia. By complaint count the order is California, Texas, Florida, New York, Illinois.[1]
What should a small city or utility do first?
Inventory what is internet-facing, remove operational technology from the public internet, change default passwords, enforce MFA on remote and privileged access, and test restoring from backups. Those five steps address the initial access vector in nearly every incident documented in this report. For structured help, start with a free cybersecurity assessment.
Cite This Report
Journalists, researchers, insurers, and public officials are welcome to cite this report with attribution. Suggested citation:
Source: "US Municipal Cyber Breach Report 2026," BlueRadius Cyber, a virtual CISO services firm. https://blueradius.io/us-municipal-cyber-breach-report-2026
For media inquiries, data questions, or the sourcing behind any figure, reach us through the contact page; we respond quickly and can point you to the underlying federal documents.
Engage a vCISO to Operationalize These Findings
Every pattern in this report, exposed controllers, untested backups, absent security leadership, is addressable with the kind of program a security executive builds. BlueRadius provides virtual CISO services to municipalities, utilities, and mid-market organizations: risk assessment, incident response readiness, vendor risk, and board-level reporting on a retainer that fits public-sector budgets.
If you want a concrete starting point, request a free cybersecurity assessment and we will map your exposure against the attack patterns documented above.
BlueRadius Research Library
- California Cybersecurity Breach Report
- Texas Cybersecurity Breach Report
- Florida Cybersecurity Breach Report
- New York Cybersecurity Breach Report
- Illinois Cybersecurity Breach Report
- Georgia Cybersecurity Breach Report
- Washington Cybersecurity Breach Report
- HIPAA Breach Report 2026
- AI Cybersecurity Incident Report 2026
- vCISO Market Report 2026
Sources
[1] Federal Bureau of Investigation, Internet Crime Complaint Center, "2025 Internet Crime Report," released April 2026. ic3.gov.
[2] Emsisoft, "The State of Ransomware in the U.S.: Report and Statistics 2024." emsisoft.com.
[3] Comparitech, "Worldwide Ransomware Roundup: 2025 End-of-Year Report." comparitech.com.
[4] Comparitech, "Government Ransomware Roundup Q1-Q3 2025." comparitech.com.
[5] Comparitech, "Government Ransomware Roundup H1 2026," with coverage by Industrial Cyber. comparitech.com.
[6] Office of the Governor of Nevada, "Nevada Completes 28-Day Recovery From Statewide Cyber Incident," November 2025; The Nevada Independent on the after-action report. gov.nv.gov.
[7] Coverage of the 2025 St. Paul cyberattack, including the Minnesota National Guard activation and Interlock leak. en.wikipedia.org.
[8] SecurityWeek, "City of Columbus Ransomware Attack Impacts 500,000 People." securityweek.com.
[9] Government Technology, "Fulton County Ransomware Attack Prompts $10M IT Overhaul"; CBS News on the county's refusal to pay. govtech.com.
[10] Government Technology, "Abilene, Texas, Replacing Infrastructure Post Cyber Attack." govtech.com.
[11] CISA, FBI, NSA, EPA, INCD joint advisory AA23-335A, "IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors," updated December 2024. cisa.gov.
[12] SecurityWeek, "Hackers Hijack Industrial Control System at US Water Utility" (Municipal Water Authority of Aliquippa); WaterISAC incident advisory. securityweek.com.
[13] FBI, CISA, NSA, EPA, DOE, USCYBERCOM-CNMF, Treasury joint advisory AA26-097A, "Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure," published April 7, 2026, updated July 22, 2026. cisa.gov.
[14] FBI and EPA Public Service Announcement I-073026-PSA, July 30, 2026. ic3.gov.
[15] Time, "What to Know About the U.S. Water Systems Cyberattacks," updated August 6, 2026; ABC News, "At Least 12 States Face Cyberattacks on Water Systems," August 4, 2026. time.com.
[16] Sophos, "The State of Ransomware in State and Local Government 2024." sophos.com.
[17] IBM, "Cost of a Data Breach Report 2025," with coverage by CyberScoop. cyberscoop.com.
[18] CISA, "State and Local Cybersecurity Grant Program: Key Changes." cisa.gov.
[19] NASCIO and Deloitte, "2026 Cybersecurity Study," April 2026. nascio.org.
[20] Center for Internet Security / MS-ISAC, "Strengthening Critical Infrastructure: SLTT Progress and Priorities, Vol. 2," August 2025. cisecurity.org.
[21] BlueRadius Cyber state breach report series, each with per-incident sourcing: California, Texas, Florida, New York, Illinois, Georgia, Washington (linked above).
[22] US Department of the Treasury, "Treasury Sanctions Actors Responsible for Malicious Cyber Activities on Critical Infrastructure," February 2, 2024. treasury.gov.
[23] US EPA, "Enforcement Alert: Drinking Water Systems to Address Cybersecurity Vulnerabilities," May 2024. epa.gov.
[24] EPA Office of Inspector General, Report 25-N-0004, November 2024, with coverage by SecurityWeek. securityweek.com.
[25] GAO-24-106744, "EPA Urgently Needs a Strategy to Address Cybersecurity Risks to Water and Wastewater Systems," August 2024. gao.gov.
[26] GAO-26-109159, "Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector," May 2026. gao.gov.
[27] Canadian Centre for Cyber Security, "Cyber Threat Bulletin: Iranian Cyber Threat Response to US-Israel Strikes," February 2026; Al Jazeera on the conflict status, August 1, 2026. cyber.gc.ca.
[28] American Water Works Association, "AWWA Urges Expanded US Cybersecurity Support Measures," August 5, 2026. prnewswire.com.
Related from the BlueRadius Library
Sourced posts on adjacent topics, ranked by tag overlap.
Compliance
HIPAA Breach Report 2026: OCR Data, Ransomware Trends, and What Mid-Market Healthcare Must Do Next
Factual 2024 HIPAA breach analysis: 276 million records exposed, 725 OCR-reported breaches, and Change Healthcare at 190 million. Fully sourced.
ReadThreat Intelligence
Florida Cybersecurity Breach Report 2025-2026: City, County & Statewide Incident Tracker
A sourced tracker of Florida city and county data breaches and ransomware (2024-2026), plus statewide IC3 losses and healthcare breaches.
ReadThreat Intelligence
Higher Education Cybersecurity Breach Report 2026: 251 Ransomware Attacks, 3.96M Records Breached
Sourced analysis of higher education cybersecurity: 251 ransomware attacks in 2025, 3.96M records, and the MOVEit cascade across 900 colleges.
ReadThreat Intelligence
CMMC Phase 2 Readiness Checklist: Nov 10, 2026 Deadline + 110 Control Path
Step-by-step CMMC 2.0 Phase 2 readiness before the November 10, 2026 deadline: all 110 NIST SP 800-171 controls, SSP and POA&M, and C3PAO assessment.
ReadThreat Intelligence
Penetration Testing vs Vulnerability Scanning: What Your Business Actually Needs (2025)
The key differences between penetration testing and vulnerability scanning, when to use each, and how to build a program that satisfies compliance.
ReadThreat Intelligence
The Executive's Guide to Digital Forensics: Protecting Your Organization Post-Breach
How digital forensics planning protects enterprise value, reduces liability, and speeds recovery after a cyber incident.
ReadRelated services