Threat reportRansomwareTL-2026-2862

City of Vicksburg, Mississippi shuts down systems after ransomware attack

mediumACTIVE

City of Vicksburg, Mississippi shuts down systems after (TL-2026-2862) is a medium-severity ransomware operation, first published 2026-10-02 and last reviewed 2026-10-04. It has no confirmed attribution, affects City of Vicksburg Municipal computer systems and Water and Gas Office, maps to 4 MITRE ATT&CK techniques (T1078, T1190, T1490), and is covered by 9 detection rules and 13 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
4MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
13Indicators of compromise

Key facts for TL-2026-2862

Threat ID
TL-2026-2862
Severity
MEDIUM
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
government administration, utilities
Target regions
North America, united states of america, Mississippi
Detection rules
9
Indicators of compromise
13
Updates
2026-10-04 · revalidated 1× · latest source

Malware and tooling in City of Vicksburg, Mississippi shuts down systems after

Malware and tooling: Grief, MEDUSA - S1220

How City of Vicksburg, Mississippi shuts down systems after works

On 2026-10-01 the City of Vicksburg, Mississippi was hit by a ransomware attack and took its computer systems offline; 911, police, fire and utility service continued but in-person utility payment processing was disrupted. No threat actor, malware family, ransom demand or technical indicators have been disclosed, and the city has not determined whether personal data was accessed.

Mayor Willis Thompson confirmed that the City of Vicksburg, Mississippi (population over 20,000, roughly 40 minutes west of Jackson) was the target of a ransomware attack on Thursday, 2026-10-01. The city brought its internet operations down 'just for protection' and described the shutdown as temporary. Reporting from The Record, WDAM and DataBreaches.Net states that city computer systems, including Water and Gas Office systems serving more than 10,000 utility accounts, were affected. In-person utility bill payments may be delayed. The city stated there will be no penalties or termination of services while the system is offline.

Emergency services were not affected: 911, the Police Department and the Fire Department remain operational, as do utility services themselves. The FBI, the Department of Homeland Security, state officials and private cybersecurity specialists are investigating. The mayor said a top priority is determining whether personal or confidential information of customers, contractors, vendors, employees or business partners was compromised, and the city committed to notifying affected parties and offering protective resources if a breach is confirmed.

Evidence limits: as of 2026-10-03 no ransomware group has claimed the attack, no malware family has been named, no ransom demand or amount has been published, no CVE or initial access vector has been disclosed, and no indicators of compromise have been released. DataBreaches.Net notes it is unclear whether files were actually encrypted or only a ransom demand was received. The ATT&CK mappings in this record are therefore ransomware-class inferences, not sourced observations, except where the reporting directly supports them (ransomware impact on systems, extortion). Mississippi has seen other recent ransomware incidents, including the University of Mississippi Medical Center in February 2026, which the Medusa group claimed with an $800,000 demand; no link between that incident and Vicksburg has been reported.

MITRE ATT&CK techniques used in TL-2026-2862

Persistence

T1078 Valid Accounts

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1490 Inhibit System Recovery; T1657 Financial Theft

Affected products and versions in City of Vicksburg, Mississippi shuts down systems after

  • City of Vicksburg — Municipal computer systems and Water and Gas Office utility billing
    Vulnerable versions: Unspecified

Remediation for City of Vicksburg, Mississippi shuts down systems after

Immediate actions

  • Keep affected municipal and utility billing systems isolated until investigators confirm scope
  • Preserve logs, disk images and ransom notes for FBI and DHS investigators
  • Reset credentials and revoke sessions for privileged and remote-access accounts
  • Use out-of-band payment channels for utility customers while systems are offline

Workarounds

  • Accept in-person and manual utility payments with no late penalties or service termination, as the city has stated

Longer-term hardening

  • Maintain offline, immutable, tested backups of billing and records systems
  • Segment utility billing and OT-adjacent networks from general municipal IT
  • Deploy EDR with ransomware behavioral detection and MFA on all remote access
  • Rehearse a municipal incident response and data-breach notification plan

Timeline of City of Vicksburg, Mississippi shuts down systems after

  • Context: Vicksburg-Warren School District hit by ransomware claimed by the Grief group; separate entity, no link to the 2026 city incident
  • Context: University of Mississippi Medical Center is hit by ransomware, later claimed by Medusa; no link to Vicksburg reported
  • 911, Police and Fire remain operational; in-person utility payment processing is disrupted and the city waives penalties and shutoffs
  • City takes internet operations and computer systems offline as a protective measure
  • City of Vicksburg is hit by a ransomware attack, per Mayor Willis Thompson
  • City states systems are being restored in a secure manner and affected parties will be notified if a compromise of personal or confidential information is confirmed.
  • The Record reports the city declined to comment on ransom demands or attacker identity; the mayor said technical details will not be disclosed so as not to interfere with the investigation, recovery or system security.
  • FBI, DHS, state officials and private cybersecurity specialists engaged; data-compromise scope undetermined
  • Mayor publicly confirms the ransomware incident; The Record, WDAM and DataBreaches.Net report it
  • No ransomware group has claimed responsibility and no malware, ransom amount or IOCs are public

Update history for TL-2026-2862

Sources cited for City of Vicksburg, Mississippi shuts down systems after

Detection coverage for TL-2026-2862

As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2862 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
13 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats