The City of Vicksburg, Mississippi, confirmed on Thursday, October 1, 2026, that it is investigating a ransomware attack that forced it to temporarily shut down its computer systems. A city notice, published in full by the Vicksburg Daily News and summarised by The Vicksburg Post, says 911, police, fire and utility services remain operational. The city has not yet determined whether personal or confidential data was accessed or taken. No ransomware group has claimed the attack publicly. The city has not said how many people may be affected, how much data may be involved or whether a ransom has been demanded.
What Happened
The city's statement says it is "investigating a cybersecurity incident resulting from a ransomware attack" that "resulted in the temporary shutdown of the City's computer systems." It has activated its incident response protocols and is working with outside cybersecurity specialists and "other appropriate partners" to investigate and restore systems securely.
Speaking to The Vicksburg Post on Thursday morning, Mayor Willis Thompson said the city took its internet operations offline as a precaution after it identified a vulnerability. "We had to bring our internet operations down, just for protection," Thompson said. "That's caused us not to be able to do some things, but we have isolated the problem."
The scale of the disruption is described differently depending on the source. The city's written notice says critical services "were not affected." Thompson gave a broader picture of the internal impact: "All of our network operations are affected. Everybody on our network is affected to some degree." These two statements can both be true. Emergency and utility operations appear to have kept running, while the city's general administrative network is degraded across every department. Readers should not take "critical services unaffected" to mean that only a small part of the network was hit.
The only service impact the city has confirmed to the public is a possible delay for in-person utility payments. The city says it will not charge penalties or cut off service while its systems are offline.
According to The Vicksburg Post, Thompson said Homeland Security officials have been working with the city and that state and FBI officials were expected in Vicksburg on Thursday. The city's own notice does not name these agencies. It refers only to "other appropriate partners."
What Was Taken
Nothing has been confirmed yet. The city says it "has not reached a final determination regarding what information, if any, may have been accessed or acquired without authorization."
The notice does say which groups of people the investigation is focused on: current and former customers, contractors, vendors, employees and affiliated business partners. For a municipality that runs utilities, the customer category probably includes utility billing records. Comparable incidents show what is usually at risk. In Fort Smith, Arkansas, OTON Technology reports that the city still had not said, 26 days into its incident, whether records tied to more than 36,000 water and sewer accounts and 1,032 employees had been touched. In McMinnville, Oregon, the News-Register reports that the city told residents names, driver's license numbers and Social Security numbers may have been exposed after a breach that RansomHouse claimed and followed with a dark web leak.
Vicksburg has committed to notifying anyone whose personal information is found to have been compromised. No leak site listing for Vicksburg has been reported in the available sources.
Why It Matters
This is the latest in a series of attacks on Mississippi public bodies this year. The Magnolia Tribune, via The Northside Sun, reports that the University of Mississippi Medical Center (UMMC) suffered a network breach in February that closed clinics. The Mississippi Institutions of Higher Learning (IHL) office was then hit on September 7, but it did not notify its member institutions until September 10. State Auditor Shad White has since asked IHL whether taxpayer money was used to pay ransoms. State Senator Nicole Boyd said she has confirmed that none was used in either case. Separately, the Mississippi Free Press reported on September 25 that Magnetic Arrow Designs, the Biloxi web designer behind the Bolivar County circuit clerk's site, was compromised and its site served foreign gambling pop-ups. That raises supply-chain concerns about small public-sector web vendors in the state.
Nothing in the sources links any of these incidents to Vicksburg. Together, though, they show sustained pressure on Mississippi's public sector, and they suggest Vicksburg's handling of the attack, including whether it pays a ransom, will draw the same auditor and legislative scrutiny.
The Fort Smith case shows the pattern that municipal ransomware usually follows: payment systems go down first, 911 is declared safe, a long outage follows and disclosure is slow. McMinnville shows the other end of that pattern. The data was taken between June 1 and July 18, 2026, and the city did not complete even part of its review until September 22. Vicksburg residents should expect a similar delay before they get any definitive answer about their data.
Note on sources: one source in this set (a Regions Bank $2.5 million donation to UMMC's Cancer Center) has no bearing on the incident beyond its connection to UMMC, the victim of the February breach.
The Attack Technique
The initial access vector has not been disclosed. Thompson told The Vicksburg Post that the city acted "after identifying a vulnerability," but he did not say whether that meant an exploited software flaw, stolen credentials, phishing or something else. The city has not named a ransomware family or threat actor, and it has not said whether data was exfiltrated before encryption. Data theft before encryption is now standard practice for most ransomware operations.
The Vicksburg Post reported on September 12 that the Board of Mayor and Aldermen approved a $12,523.31 statement of work with CivicPlus to rebuild the city website, including security upgrades. Nothing in the reporting connects that project, or CivicPlus, to this attack. It is mentioned here only because the city's web infrastructure was in transition when the attack happened, which is a known period of elevated risk.
What Organizations Should Do
- Separate emergency services from the corporate network. Vicksburg's 911, police, fire and utility operations kept running while "everybody on our network" was affected. Confirm that your CAD, dispatch and SCADA/utility control systems cannot be reached from the general IT network, and test that they can run with corporate IT fully disconnected.
- Have manual payment and billing fallbacks ready. Fort Smith dropped to cash and checks overnight, and Vicksburg warns of payment delays. Pre-approve no-penalty policies and offline receipt procedures so residents are not penalised for the city's outage.
- Assume data was stolen until you can prove otherwise. Keep enough logging (EDR, firewall egress, VPN, identity provider) and retain it long enough to determine whether exfiltration happened. Without it, reviews stretch into months, as they did in McMinnville.
- Audit web and SaaS vendors. The Magnetic Arrow Designs compromise shows how a small vendor can become a weak link. During website migrations, inventory admin accounts, remove legacy access and require MFA on vendor portals.
- Patch internet-facing systems and require MFA on them. Without a disclosed vector, prioritise the usual municipal entry points: VPN appliances, remote access, exposed RDP and unpatched edge devices.
- Agree on ransom and notification policy in advance. Mississippi's State Auditor is now asking public bodies about ransom payments and breach dates. Document decision authority, funding rules and notification timelines with legal counsel and the relevant state IT agency before an incident.
Sources: Ransomware attack shuts down Vicksburg computer systems | City issues release on cyberattack | Regions Bank commits $2.5M to UMMC Cancer Center and | Vicksburg approves overhaul of city website | State Auditor seeks details on cyberattacks at UMMC, IHL The North... | Bolivar County Circuit Clerk Website Designer Hacked | City notifies residents of recent hack | Fort Smith Computer Attack Still Active After 26 Days