Cyber & AI intelligence
Wasteland.
Briefs indexed2890
Issues29
Published Mondays07:30 CT
█ Ransomware ANDOVER-MA-RANSOMW 2026-09-27

Town of Andover: Ransomware Attack Claimed by WallStreet Group

"A cyberattack detected on August 13, 2026 knocked out the shared municipal and school network in Andover, Massachusetts for four days. Town Manager Andrew Flanagan confirmed the cause. Town records obtained by Andover…"

A cyberattack detected on August 13, 2026 knocked out the shared municipal and school network in Andover, Massachusetts for four days. Town Manager Andrew Flanagan confirmed the cause. Town records obtained by Andover News show that on the first night of the incident, the Town signed a contract for "ransomware investigation and response services" with outside counsel and a forensic firm. On August 30 the WallStreet ransomware group listed Andover on its dark-web leak site. The claim has not been independently verified, and the Town has not attributed the attack to any group. The Town has also not said whether it received a ransom demand, talked to the attacker, or lost data. It has withheld the records that would answer those questions, citing an "active, ongoing municipal investigation."

What Happened

On August 13 the Town first described the problem as a "temporary issue impacting internet connectivity" that could disrupt services, including email to staff. Later reporting shows the Town treated it as a ransomware event from the start. According to contracts reviewed by Andover News, that same evening the Town signed an agreement with the law firm Constangy, Brooks, Smith & Prophete and the cybersecurity firm Vector3. Vector3's job was to:

The records put the initial response cost at no less than $39,605, with a possible total above $44,000. The Town filed a cyberinsurance claim within days.

The Town and Andover Public Schools share one IT organization and one network, so the outage hit both. DysruptionHub reports that the attack disrupted:

A district update said internet and email problems were still ongoing on August 14. By August 17 the Town said email and most online services were working again, though bill payments could still fail. According to vpn.social, the Town's MUNIS financial and payroll system was restored from a backup taken at midnight on August 12, and any work done after that point had to be re-entered by hand.

Flanagan said Town buildings stayed open, phones kept working, and public safety, utilities and other infrastructure were not interrupted. "The Town was well prepared to respond to an event of this nature," he said.

The sources disagree slightly on when the Town first publicly confirmed a cyberattack. Andover News originally reported a Flanagan email sent Friday, August 22. A later Andover News piece, republished by National Cyber Security, gives the date as August 21. Either way, the Town confirmed the attack about eight to nine days after first calling it a connectivity problem.

What Was Taken

This has not been confirmed. The Town has not said whether any Town or school data was accessed, copied or stolen.

Leak-site listings alone do not prove a breach. Groups sometimes exaggerate, reuse old data or post false claims. However, the listing came about two weeks after the intrusion, and the Town's contract included negotiation services. Both fit a typical double-extortion pattern.

Why It Matters

The Attack Technique

Unknown. No source identifies how the attackers got in, and the Town has not disclosed it. Finding the entry point was part of Vector3's assignment, and those findings have not been made public. WallStreet is a relatively little-documented group, and none of the sources describe its usual tools or methods. The August 30 "estimated attack date" on Ransomware.live is simply the date the listing was posted, not the date of the intrusion, which was August 13.

What Organizations Should Do

  1. Pre-contract your incident response. Have outside counsel and a forensic firm on retainer, with engagement terms already approved by your insurer, so you can sign on day one as Andover did.
  2. Segment shared town and school networks. Where IT is shared, separate the environments so one compromise cannot take both offline.
  3. Keep frequent, offline or immutable backups of critical systems such as MUNIS, finance and payroll, and test restores regularly so you know the recovery point and how much work will need re-entering.
  4. Isolate public safety, phone and utility systems from the general enterprise network. That separation is what kept those services running in Andover.
  5. Plan for disclosure, not just recovery. Prepare holding statements that are accurate without prejudicing the investigation. Calling a ransomware event a "connectivity issue" costs public trust once records come out.
  6. Watch leak sites for your organization's name using services like Ransomware.live or RansomLook, so a public claim does not catch you off guard.

Sources: Records: Andover Hired Ransomware Specialists On First Night Of Cyb... | Cyberattack Caused Four-Day Network Outage For Town, APS Andover News | Andover cyberattack: Most town and school systems restored | Andover Ransomware Attack: Records Show Delayed Disclosure — vpn.so... | Ransomware Group Claims Andover As Victim Following Cyberattack #r... | Ransomware.live - Victim: Andover | Andover Town and Schools Cyberattack