SYS::ONLINE
Wasteland.
Briefs1691
Issues22
SinceFeb 2026
LIVE
▣ Breach PASSAIC-COUNTY-NJ 2026-08-04

Passaic County, New Jersey: March Ransomware Attack Costs $395K With No Ransom Paid

"Passaic County, New Jersey has confirmed that a March 2026 ransomware attack knocked its network offline, resulted in the theft of county data, and produced a ransom demand the county refused to pay. The refusal did not…"

Passaic County, New Jersey has confirmed that a March 2026 ransomware attack knocked its network offline, resulted in the theft of county data, and produced a ransom demand the county refused to pay. The refusal did not make the incident cheap. County commissioners approved nearly $147,000 in additional cybersecurity and recovery spending on July 14, bringing total authorized response costs to roughly $395,000, according to NorthJersey.com's reporting on county records and statements from county spokesperson Lindsay Reed. Systems have been restored and the forensic investigation is complete, but a separate review to determine exactly whose data was taken remains open more than four months after detection.

What Happened

County records place detection of suspicious activity at approximately March 4, 2026. The July 14 commissioners' agenda describes the incident plainly as a "Ransomware Event." The operational damage was broad rather than surgical: NorthJersey.com reports the attack rendered the county's network inoperable, including phone systems, computers, and internet service. That is a full enterprise outage for a county government serving roughly half a million residents, not a contained departmental disruption.

County officials confirmed that the attackers accessed and obtained data from county systems and issued a ransom demand. Their statement on payment is unusually specific and worth quoting in structure: no payment was made by the county, its insurer, or anyone working on its behalf. That third clause matters, because it forecloses the common arrangement where a breach counsel or negotiator settles quietly while the victim organization maintains it never paid.

The spending trail runs through MOXFIVE, an incident response firm engaged during the initial response. The county initially authorized $149,375 for MOXFIVE plus $8,250 for the firm to obtain additional information. The July 14 allocation pushed MOXFIVE's contract past $304,000. Reed said MOXFIVE restored county systems and conducted forensic analysis under the direction of outside legal counsel, and is now reviewing the involved data so the county can determine its notification obligations.

One account goes further than the others. PressReleaseCloud.io, a low-tier aggregator, characterizes the malware as a variant of the LockBit 3.0 family and claims it encrypted departmental servers handling payroll, property records, and public safety communications. No county statement and no established outlet in this source set corroborates either the attribution or that department list. Treat it as unverified: the county has not publicly named a threat actor or ransomware family.

What Was Taken

The honest answer is that nobody outside the county's data review knows yet, and the county says so. As of early August 2026, officials have not disclosed how much data was taken, whether any of it appeared on a leak site, or how many employees, residents, or third parties may be affected. The data review is specifically intended to answer whether New Jersey breach notification duties are triggered.

There is, however, a strong candidate for one downstream victim population. Two secondary outlets, write4good.com and marinaidsproject.org, both report a breach at Preakness Healthcare Center, a county-run nursing home in Passaic County, with an intrusion window of February 24 to March 4 and discovery on March 4. That discovery date is the same day the county detected suspicious activity on its own network. Both accounts describe stolen files containing resident names, demographic information, and limited clinical care details, limited to residents admitted after January 1, 2019, with notification letters and complimentary credit monitoring offered.

Both are OTHER-tier sources and neither the county nor any primary filing in this source set explicitly links the Preakness notification to the county network event. The date overlap is suggestive, not confirmed. If the two are the same incident, the county is dealing with protected health information exposure on top of general government records, which materially raises its regulatory exposure.

For scale context on New Jersey's wider breach environment during the same period: HIPAA Journal reports Centers Lab NJ LLC notified 542,377 individuals over an August 2025 intrusion, and GovTech and WPG Talk Radio both report that a compromise at law firm Greenbaum Rowe Smith and Davis exposed data on 12,801 patients across Atlantic Health System, Hackensack Meridian Health, and Trinitas Regional Medical Center. These are separate incidents with no reported connection to Passaic County.

Why It Matters

The headline number is the useful one for defenders building a business case. Passaic County paid no ransom and still authorized roughly $395,000 in response costs, with more than $304,000 of that going to a single incident response vendor. That figure covers containment, forensics, and restoration. It does not include staff overtime, the productivity cost of an inoperable phone and network environment, notification and credit monitoring costs still to come, or any litigation that follows. The true cost of this incident will exceed $395,000, possibly by a wide margin.

The refusal to pay is the strategically interesting part. The county absorbed a full network outage and rebuilt rather than buying a decryptor, and it explicitly closed the "someone else paid on our behalf" loophole in its public statement. That is the outcome ransomware policy advocates argue for, and it comes with a visible, quantified price tag. County governments budgeting for cyber risk should read $400,000 as the floor for a mid-size municipal ransomware event where recovery goes reasonably well.

The five-month gap between detection and answers on data scope is its own lesson. Forensics finished quickly; data review did not. Determining which individuals appear in a multi-terabyte exfiltration set is slow, expensive, and largely manual, and it is the phase that generates legal exposure. Organizations that cannot say what was in a given file share will pay for someone to find out.

The Attack Technique

Initial access vector has not been disclosed. No county statement identifies how the attackers entered, what tooling they used, or how long they had access before deployment. The publicly available timeline is thin: suspicious activity detected around March 4, network-wide encryption and outage, data exfiltration confirmed, ransom demand issued.

If the Preakness Healthcare Center reporting describes the same intrusion, it supplies a dwell time estimate of roughly nine days, February 24 to March 4, which is consistent with a modern double-extortion operation: gain access, escalate, stage and exfiltrate data, then detonate encryption as the final step. That pattern is why exfiltration was already complete before anyone noticed anything was wrong.

The LockBit 3.0 attribution from PressReleaseCloud.io is the only actor claim in the source set and it stands alone. Do not build detection or reporting on it.

What Organizations Should Do

  1. Budget for a no-ransom recovery, not a ransom. Model your worst case as full network rebuild plus outside forensics plus data review. Passaic County's $395,000 and climbing is a realistic reference point for a county-scale environment, and cyber insurance should be evaluated against that number rather than against a hypothetical ransom.
  2. Assume exfiltration precedes encryption and instrument for it. Detection of large outbound transfers, unusual archive creation, and access to file shares outside a user's normal pattern buys you the window before detonation. Encryption is the last event, not the first.
  3. Segment critical services so one intrusion cannot take phones, internet, and computing at once. The reported total loss of voice and network service turned a data incident into a continuity-of-government incident. Out-of-band emergency communications should not depend on the same infrastructure being encrypted.
  4. Know your data before you have to inventory it under pressure. The county's open-ended data review is the expensive part. Maintaining a current map of where regulated data lives, particularly PHI in county-run health facilities, converts a five-month discovery project into a targeted query.
  5. Enforce phishing-resistant MFA and tighten access controls on administrative accounts. These are the measures the county itself is reportedly folding into policy alongside regular vulnerability assessments, and they remain the highest-yield controls against the credential-driven access that dominates this class of intrusion.
  6. Pre-engage counsel and an IR retainer, and understand New Jersey's notification duty. As Mindcore notes in its compliance guidance for New Jersey businesses, N.J.S. breach notification obligations attach to personal data on state residents regardless of whether a federal framework applies. Running forensics under privilege via outside counsel, as Passaic County did, is the correct structure. Establish it before the incident, not during.

Sources: Passaic County Suffers $400K Cyberattack Fallout Without Paying Ran... | Centers Laboratory Discloses Data Breach Affecting 542K Individuals | Passaic County didn't pay ransom, but cyberattack still cost ... | N.J. Nursing Home Hacked: Residents' Data at Risk (2026) | Nursing Home Hack: Personal Data Breach Affects Residents (2026) | New Jersey Cyber Attack May Have Exposed Patient Data | Secure Your Business with IT Services Fairfield Mindcore | Nearly 13,000 NJ patients affected by health care data breach