The Interlock ransomware group has claimed responsibility for the cyberattack that knocked parts of the City of Fort Smith, Arkansas municipal network offline for the better part of a month, according to listings on Ransom-DB and DysruptionHub reported by Talk Business & Politics. The city itself has never used the word "ransomware." What Fort Smith has confirmed, in a Sept. 15 statement from City Administrator Jeff Dingman, is narrower but more consequential: a threat actor got into the city's systems through the Fort Smith Police Department and exfiltrated data. Interlock claims the haul was 5,720 gigabytes, roughly 5.7 terabytes. Potentially in scope are 1,032 city employees, more than 36,000 residents and businesses holding water and sewer accounts, city vendors, and records tied to the municipal judicial system.
What Happened
Fort Smith identified what it called a "cybersecurity event" on Aug. 16, 2026, and disclosed it publicly the same day in a Sunday news release. The initial disclosure was deliberately thin: certain computer systems were disrupted, 911 dispatch and emergency response were "fully functional," and the city was coordinating with governmental partners including federal law enforcement and outside cybersecurity specialists.
The operational damage surfaced fast. By Monday, Aug. 17, the Northwest Arkansas Democrat-Gazette reported that city offices at 623 Garrison Ave. could accept only cash and checks for utility bills, permits, and other services, with no credit or debit card processing available. Landfill scale house services went cash-and-check only in a separate release the same day. Those are the kinds of outages that tell you the payment processing tier and the segments it touches were either encrypted, isolated as a precaution, or both.
Nearly a month later, on Sept. 15, the Board of Directors went into executive session with Dingman and Chief Information Officer James Gentry. The statement that followed that evening is the most substantive thing the city has said:
"The forensic investigation of the cybersecurity event is nearing conclusion, and we have assurance that the threat has been contained. The investigation determined that an unauthorized threat actor accessed the City's systems through the Fort Smith Police Department and exfiltrated certain data. The City has identified how the threat actor gained access to its systems and the scope of the information accessed."
Dingman added that systems were being restored "only when they can be returned to service safely," and that payment systems at City Hall, Fort Smith District Court, and the Fort Smith Landfill are back online, with all public-facing city services restored. The city says it is now reviewing the data involved against applicable breach notification requirements and plans to implement additional security measures.
What the city still will not say is whether personal or financial data of residents, employees, or vendors was compromised, whether a ransom demand was made, or which internal systems remain degraded. Talk Business & Politics has noted plainly that because the city declines to answer questions, those facts are currently unknowable from the outside.
What Was Taken
Here the accounts diverge, and the spread matters.
Volume. Talk Business & Politics, citing the Ransom-DB listing, reports Interlock's claim at 5,720 GB, about 5.7 TB. Undercode News published a headline claiming "56 TB" while its own body text says "approximately 5.6 TB," attributing that figure to a report from Cybersecurity News Everyday. Treat the 56 TB headline as an error; the two body-level figures, 5.7 TB and 5.6 TB, are consistent with each other and with a single leak-site listing being rounded differently. The city has confirmed only that "certain data" was exfiltrated and has given no volume of its own.
Content. Per the Ransom-DB post as relayed by Talk Business & Politics, Interlock claims it took a wide range of sensitive material including police photographs, water supply system information, and data from "computer systems and networks that support the operations of various departments of the city." Undercode News reports the alleged dataset also includes fire and emergency response records, infrastructure records, and more than 100,000 Social Security numbers. That SSN figure appears in only one lower-tier source, sourced in turn to a third party, and should not be treated as established. It is also notably larger than Fort Smith's combined employee and utility-account populations, which is a reason for caution rather than confidence.
Who is exposed. This part comes from local reporting and is more solid: 1,032 city employees, more than 36,000 residents and businesses with water and sewer accounts, an unspecified vendor population, and information the city holds for judicial system use. Nobody outside the forensic engagement can say yet how much of that population is actually inside the exfiltrated set. No leak-site publication of the data has been reported as of this writing, which is consistent with Interlock's pattern of staging a claim before dumping.
The honest summary: the city confirms exfiltration and says it knows the scope. The scope has not been shared. Everything specific about content and volume currently comes from the attacker.
Why It Matters
Interlock is not an opportunistic smash-and-grab. Sophos, which tracks the group as GOLD EMBRACE, describes it as a small, dedicated team that writes its own malware and runs its own intrusions rather than operating as a Ransomware-as-a-Service affiliate program. That structure means consistent tradecraft across victims and no affiliate noise to hide behind, which is good for defenders trying to build detections and bad for victims, because the operators are experienced and deliberate. The group emerged in September 2024 and currently concentrates on North American and European targets in critical infrastructure, healthcare, and education. FortiGuard Labs adds government and manufacturing to the targeted-industry list. Fort Smith fits.
The entry point is the part defenders should sit with. A police department is not a peripheral system. It is a network segment holding evidence files, investigative photographs, criminal history queries, and in many municipalities live CJIS-connected infrastructure. Compromising it and pivoting outward into finance, utilities, and the landfill scale house says the city's internal segmentation between law enforcement and general municipal IT was either absent or insufficient to stop lateral movement. That architecture is the norm in mid-sized American cities, not an outlier.
There is a second-order problem specific to municipal victims. A city cannot simply issue a credit monitoring offer and move on. Stolen police photographs may include victims, minors, confidential informants, and active-case material. Water and sewer account data is tied to physical addresses. Judicial records carry their own confidentiality obligations. The downstream harm surface is not a corporate PII spreadsheet, and the notification analysis Fort Smith is now running is correspondingly harder than a standard breach workflow.
Finally, the month-long gap between disclosure and "nearing conclusion" is itself the lesson. Fort Smith kept 911 up, which is the thing that mattered most, but residents spent weeks unable to pay bills by card, and the city is only now reaching the point where it can say what was taken.
The Attack Technique
The city has said it knows how the threat actor got in and has not said what that was. So the following is Interlock's documented tradecraft, not a confirmed reconstruction of this intrusion.
Sophos reports that Interlock has been actively exploiting CVE-2026-20131, a critical-severity zero-day in Cisco Secure Firewall Management Center (FMC) Software. FortiGuard Labs independently lists that CVE among the group's exploited vulnerabilities, alongside a long tail of others spanning Veeam, IP camera firmware (CVE-2017-7921), and roughly two dozen more. An internet-facing firewall management plane is exactly the kind of asset that would give an attacker a foothold with broad reach.
Beyond that, the group's documented playbook includes:
- ClickFix-style social engineering, where users are induced to paste attacker-supplied commands into a Run dialog or terminal under the guise of fixing a problem or completing a CAPTCHA.
- NodeSnake RAT, also called Interlock RAT, a custom-built remote access trojan, plus a PHP-based backdoor for cross-platform persistence. Interlock targets Windows, Linux, and FreeBSD.
- Abuse of legitimate DFIR tooling. In a March 2026 engagement, the Sophos Emergency Incident Response team observed Interlock running Volatility3, a legitimate memory forensics framework, on the Patient Zero host before responders arrived. Memory analysis in an attacker's hands is a credential harvesting technique that leaves a signed, legitimate binary in the logs.
- Commodity and living-off-the-land tooling per FortiGuard: Cobalt Strike, AnyDesk, PuTTY and plink, rclone, WinSCP, AzCopy and Azure Storage Explorer for staged exfiltration, and infostealers including Lumma and Berserk.
- Initial access via valid accounts, exposed RDP and VPN, public-facing application exploitation, and initial access brokers.
One detail from the Sophos writeup generalizes well beyond Interlock: in that incident the victim environment mixed Sophos-managed servers with Defender-managed endpoints, and investigators found that not all endpoints were running any protection at all. Coverage gaps in mixed-vendor estates are where these intrusions start.
Interlock practices double extortion, stealing data before encrypting and threatening publication on its "Worldwide Secrets Blog." That is consistent with the Fort Smith pattern: exfiltration confirmed by the city, a volume claim posted to leak-tracking sites, and no public dump yet.
What Organizations Should Do
-
Patch CVE-2026-20131 in Cisco Secure Firewall Management Center now, and audit the management plane for prior compromise. Interlock is exploiting this in the wild per Sophos and FortiGuard. Patching alone is insufficient if the device was already touched; review admin accounts, configuration changes, and outbound connections from the FMC host. Extend the same scrutiny to the other CVEs FortiGuard attributes to the group, particularly internet-facing backup, camera, and remote access infrastructure.
-
Segment law enforcement networks from general municipal IT, and prove it. Fort Smith's confirmed entry point was the police department, and the impact reached utility billing and landfill operations. Run an actual lateral movement test from a simulated compromised PD workstation to finance and utility systems. If the path exists, the segmentation does not.
-
Alert on legitimate DFIR and admin tooling executing outside change windows. Volatility3, rclone, AzCopy, Azure Storage Explorer, WinSCP, plink, and AnyDesk are all normal in some contexts and all Interlock tooling. Build allowlists of who is permitted to run them from where, and alert on everything else. Large outbound transfers to cloud storage endpoints from servers that have no business talking to them are the highest-value exfiltration signal you have.
-
Close EDR coverage gaps before they become the foothold. Sophos found unprotected endpoints inside a mixed-vendor environment. Reconcile your EDR console inventory against your asset inventory and your DHCP leases, not against itself, and treat every unmanaged device as an unmonitored one.
-
Harden against ClickFix. Restrict or monitor the Windows Run dialog via policy where feasible, log PowerShell and script block execution, and brief staff specifically on the "paste this command to verify you are human" pattern. This is a user-facing technique that technical controls only partially cover.
-
Write the municipal breach notification playbook before you need it. Fort Smith took a month to get from disclosure to scope determination and is only now assessing notification obligations. Pre-identify which record categories carry which state and federal obligations, particularly law enforcement, judicial, and utility customer data, and pre-establish counsel and forensic retainers so the clock starts on day one rather than day thirty.
-
Assume exfiltrated data will surface even if you never see an encryptor. Interlock's model is publication pressure. Monitor leak sites for your own name and your vendors', and treat credential material in any stolen dataset as burned. Force rotation rather than waiting for confirmation of what was in the dump.
Sources: Interlock claims responsibility for Fort Smith computer system atta... | Interlock ransomware gang creates volatile situation SOPHOS | Fort Smith computer attack investigation nearing an end - Talk Busi... | Fort Smith Ransomware Crisis: Interlock Claims a 56 TB Data Leak Fr... | City of Fort Smith Arkansas Data Breach in 2026 | City of Fort Smith reports it cannot accept card payments at 2 loca... | Dingman: Cybersecurity event started after Fort Smith Police Depart... | Threat Actor FortiGuard Labs