Threat reportRansomwareTL-2026-2862
City of Vicksburg, Mississippi shuts down systems after ransomware attack
City of Vicksburg, Mississippi shuts down systems after (TL-2026-2862) is a medium-severity ransomware operation, first published 2026-10-02 and last reviewed 2026-10-04. It has no confirmed attribution, affects City of Vicksburg Municipal computer systems and Water and Gas Office, maps to 4 MITRE ATT&CK techniques (T1078, T1190, T1490), and is covered by 9 detection rules and 13 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 4MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 13Indicators of compromise
Key facts for TL-2026-2862
- Threat ID
- TL-2026-2862
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- government administration, utilities
- Target regions
- North America, united states of america, Mississippi
- Detection rules
- 9
- Indicators of compromise
- 13
- Updates
- 2026-10-04 · revalidated 1× · latest source
Malware and tooling in City of Vicksburg, Mississippi shuts down systems after
Malware and tooling: Grief, MEDUSA - S1220
How City of Vicksburg, Mississippi shuts down systems after works
On 2026-10-01 the City of Vicksburg, Mississippi was hit by a ransomware attack and took its computer systems offline; 911, police, fire and utility service continued but in-person utility payment processing was disrupted. No threat actor, malware family, ransom demand or technical indicators have been disclosed, and the city has not determined whether personal data was accessed.
Mayor Willis Thompson confirmed that the City of Vicksburg, Mississippi (population over 20,000, roughly 40 minutes west of Jackson) was the target of a ransomware attack on Thursday, 2026-10-01. The city brought its internet operations down 'just for protection' and described the shutdown as temporary. Reporting from The Record, WDAM and DataBreaches.Net states that city computer systems, including Water and Gas Office systems serving more than 10,000 utility accounts, were affected. In-person utility bill payments may be delayed. The city stated there will be no penalties or termination of services while the system is offline.
Emergency services were not affected: 911, the Police Department and the Fire Department remain operational, as do utility services themselves. The FBI, the Department of Homeland Security, state officials and private cybersecurity specialists are investigating. The mayor said a top priority is determining whether personal or confidential information of customers, contractors, vendors, employees or business partners was compromised, and the city committed to notifying affected parties and offering protective resources if a breach is confirmed.
Evidence limits: as of 2026-10-03 no ransomware group has claimed the attack, no malware family has been named, no ransom demand or amount has been published, no CVE or initial access vector has been disclosed, and no indicators of compromise have been released. DataBreaches.Net notes it is unclear whether files were actually encrypted or only a ransom demand was received. The ATT&CK mappings in this record are therefore ransomware-class inferences, not sourced observations, except where the reporting directly supports them (ransomware impact on systems, extortion). Mississippi has seen other recent ransomware incidents, including the University of Mississippi Medical Center in February 2026, which the Medusa group claimed with an $800,000 demand; no link between that incident and Vicksburg has been reported.
MITRE ATT&CK techniques used in TL-2026-2862
Persistence
Initial Access
T1190 Exploit Public-Facing Application
Impact
Affected products and versions in City of Vicksburg, Mississippi shuts down systems after
- City of Vicksburg — Municipal computer systems and Water and Gas Office utility billing
Vulnerable versions: Unspecified
Remediation for City of Vicksburg, Mississippi shuts down systems after
Immediate actions
- Keep affected municipal and utility billing systems isolated until investigators confirm scope
- Preserve logs, disk images and ransom notes for FBI and DHS investigators
- Reset credentials and revoke sessions for privileged and remote-access accounts
- Use out-of-band payment channels for utility customers while systems are offline
Workarounds
- Accept in-person and manual utility payments with no late penalties or service termination, as the city has stated
Longer-term hardening
- Maintain offline, immutable, tested backups of billing and records systems
- Segment utility billing and OT-adjacent networks from general municipal IT
- Deploy EDR with ransomware behavioral detection and MFA on all remote access
- Rehearse a municipal incident response and data-breach notification plan
Timeline of City of Vicksburg, Mississippi shuts down systems after
- Context: Vicksburg-Warren School District hit by ransomware claimed by the Grief group; separate entity, no link to the 2026 city incident
- Context: University of Mississippi Medical Center is hit by ransomware, later claimed by Medusa; no link to Vicksburg reported
- 911, Police and Fire remain operational; in-person utility payment processing is disrupted and the city waives penalties and shutoffs
- City takes internet operations and computer systems offline as a protective measure
- City of Vicksburg is hit by a ransomware attack, per Mayor Willis Thompson
- City states systems are being restored in a secure manner and affected parties will be notified if a compromise of personal or confidential information is confirmed.
- The Record reports the city declined to comment on ransom demands or attacker identity; the mayor said technical details will not be disclosed so as not to interfere with the investigation, recovery or system security.
- FBI, DHS, state officials and private cybersecurity specialists engaged; data-compromise scope undetermined
- Mayor publicly confirms the ransomware incident; The Record, WDAM and DataBreaches.Net report it
- No ransomware group has claimed responsibility and no malware, ransom amount or IOCs are public
Update history for TL-2026-2862
- 2026-10-04 — City of Vicksburg, Mississippi Takes Systems Offline After Reported Ransomware Attack: What changed No field changes. Recovery has begun (secure restoration underway) and the city has publicly declined to discuss ransom demands, attacker identity or technical details. New indicators (2) Two additional context entities (Missis
Sources cited for City of Vicksburg, Mississippi shuts down systems after
- Mississippi mayor says ransomware incident led city to shut down systems
- City of Vicksburg hit by ransomware cyberattack, mayor says
- City of Vicksburg, Mississippi, shuts down computers after cyberattack
- Ransomware Attack Shuts Down Vicksburg City Systems
- Mississippi school districts targeted by ransomware attacks (2021 local context)
- Cybercriminals say they hacked UMMC, demand ransom
- Mississippi hospital system closes all clinics after ransomware attack
Detection coverage for TL-2026-2862
As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2862 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.