A cyberattack detected on August 13, 2026 knocked out the shared municipal and school network in Andover, Massachusetts for four days. Town Manager Andrew Flanagan confirmed the cause. Town records obtained by Andover News show that on the first night of the incident, the Town signed a contract for "ransomware investigation and response services" with outside counsel and a forensic firm. On August 30 the WallStreet ransomware group listed Andover on its dark-web leak site. The claim has not been independently verified, and the Town has not attributed the attack to any group. The Town has also not said whether it received a ransom demand, talked to the attacker, or lost data. It has withheld the records that would answer those questions, citing an "active, ongoing municipal investigation."
What Happened
On August 13 the Town first described the problem as a "temporary issue impacting internet connectivity" that could disrupt services, including email to staff. Later reporting shows the Town treated it as a ransomware event from the start. According to contracts reviewed by Andover News, that same evening the Town signed an agreement with the law firm Constangy, Brooks, Smith & Prophete and the cybersecurity firm Vector3. Vector3's job was to:
- work out how the attackers got in and reconstruct what they did
- find out whether data was accessed or taken
- forensically examine up to 10 systems
- monitor more than 3,000 devices
- if necessary, communicate directly with the attacker
The records put the initial response cost at no less than $39,605, with a possible total above $44,000. The Town filed a cyberinsurance claim within days.
The Town and Andover Public Schools share one IT organization and one network, so the outage hit both. DysruptionHub reports that the attack disrupted:
- staff email (the Town took external email offline)
- online bill payments
- the release of teacher assignments to school families shortly before the school year
A district update said internet and email problems were still ongoing on August 14. By August 17 the Town said email and most online services were working again, though bill payments could still fail. According to vpn.social, the Town's MUNIS financial and payroll system was restored from a backup taken at midnight on August 12, and any work done after that point had to be re-entered by hand.
Flanagan said Town buildings stayed open, phones kept working, and public safety, utilities and other infrastructure were not interrupted. "The Town was well prepared to respond to an event of this nature," he said.
The sources disagree slightly on when the Town first publicly confirmed a cyberattack. Andover News originally reported a Flanagan email sent Friday, August 22. A later Andover News piece, republished by National Cyber Security, gives the date as August 21. Either way, the Town confirmed the attack about eight to nine days after first calling it a connectivity problem.
What Was Taken
This has not been confirmed. The Town has not said whether any Town or school data was accessed, copied or stolen.
- The WallStreet listing: Ransomware.live and RansomLook both record WallStreet adding "Andover" to its leak site on August 30, 2026, with a description of the Town's municipal services.
- Sources disagree on what the group claims to hold. Andover News said the listing did not identify any data, volume or released files. DysruptionHub's later incident profile says WallStreet "claimed possession of several data categories" but does not list them. Neither account has been verified.
- Staff notification: According to vpn.social, Flanagan told employees on August 17 that investigators were still working out whether personal or sensitive information was affected. No other source reports this.
- Scope of the forensic work: The contracts included forensic work to find out whether data had been exfiltrated. That is standard scoping for this kind of engagement and does not prove data was taken.
Leak-site listings alone do not prove a breach. Groups sometimes exaggerate, reuse old data or post false claims. However, the listing came about two weeks after the intrusion, and the Town's contract included negotiation services. Both fit a typical double-extortion pattern.
Why It Matters
- Shared infrastructure means a shared outage. Because the town and school district share a network, one intrusion disrupted both municipal services and school operations. DysruptionHub notes that a November 2025 incident in Attleboro, Massachusetts also took municipal systems offline.
- Public statements lagged behind the internal response. The Town hired ransomware responders on day one but described the incident as a connectivity issue for more than a week. It still has not said whether ransomware was involved. Residents whose data may be exposed have little to go on.
- Recent backups limited the damage. The Town kept public safety running and restored its financial system from a backup less than 24 hours old, which suggests incident response planning and backups paid off.
- Cyberinsurance shaped the response. Signing the counsel and forensics agreement that same evening follows the common insurer-driven model, where outside counsel hires the forensic firm to preserve legal privilege. That model also tends to slow public disclosure.
The Attack Technique
Unknown. No source identifies how the attackers got in, and the Town has not disclosed it. Finding the entry point was part of Vector3's assignment, and those findings have not been made public. WallStreet is a relatively little-documented group, and none of the sources describe its usual tools or methods. The August 30 "estimated attack date" on Ransomware.live is simply the date the listing was posted, not the date of the intrusion, which was August 13.
What Organizations Should Do
- Pre-contract your incident response. Have outside counsel and a forensic firm on retainer, with engagement terms already approved by your insurer, so you can sign on day one as Andover did.
- Segment shared town and school networks. Where IT is shared, separate the environments so one compromise cannot take both offline.
- Keep frequent, offline or immutable backups of critical systems such as MUNIS, finance and payroll, and test restores regularly so you know the recovery point and how much work will need re-entering.
- Isolate public safety, phone and utility systems from the general enterprise network. That separation is what kept those services running in Andover.
- Plan for disclosure, not just recovery. Prepare holding statements that are accurate without prejudicing the investigation. Calling a ransomware event a "connectivity issue" costs public trust once records come out.
- Watch leak sites for your organization's name using services like Ransomware.live or RansomLook, so a public claim does not catch you off guard.
Sources: Records: Andover Hired Ransomware Specialists On First Night Of Cyb... | Cyberattack Caused Four-Day Network Outage For Town, APS Andover News | Andover cyberattack: Most town and school systems restored | Andover Ransomware Attack: Records Show Delayed Disclosure — vpn.so... | Ransomware Group Claims Andover As Victim Following Cyberattack #r... | Ransomware.live - Victim: Andover | Andover Town and Schools Cyberattack