# City of Vicksburg, Mississippi shuts down systems after ransomware attack

> On 2026-10-01 the City of Vicksburg, Mississippi was hit by a ransomware attack and took its computer systems offline; 911, police, fire and utility service continued but in-person utility payment processing was disrupted. No threat actor, malware family, ransom demand or technical indicators have been disclosed, and the city has not determined whether personal data was accessed.

- **Published:** 2026-10-02T00:00:00Z
- **Last reviewed:** 2026-10-04T01:31:17.997Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2862
- **ID:** TL-2026-2862
- **Severity:** MEDIUM
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 13 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Mayor Willis Thompson confirmed that the City of Vicksburg, Mississippi (population over 20,000, roughly 40 minutes west of Jackson) was the target of a ransomware attack on Thursday, 2026-10-01. The city brought its internet operations down 'just for protection' and described the shutdown as temporary. Reporting from The Record, WDAM and DataBreaches.Net states that city computer systems, including Water and Gas Office systems serving more than 10,000 utility accounts, were affected. In-person utility bill payments may be delayed. The city stated there will be no penalties or termination of services while the system is offline.

Emergency services were not affected: 911, the Police Department and the Fire Department remain operational, as do utility services themselves. The FBI, the Department of Homeland Security, state officials and private cybersecurity specialists are investigating. The mayor said a top priority is determining whether personal or confidential information of customers, contractors, vendors, employees or business partners was compromised, and the city committed to notifying affected parties and offering protective resources if a breach is confirmed.

Evidence limits: as of 2026-10-03 no ransomware group has claimed the attack, no malware family has been named, no ransom demand or amount has been published, no CVE or initial access vector has been disclosed, and no indicators of compromise have been released. DataBreaches.Net notes it is unclear whether files were actually encrypted or only a ransom demand was received. The ATT&CK mappings in this record are therefore ransomware-class inferences, not sourced observations, except where the reporting directly supports them (ransomware impact on systems, extortion). Mississippi has seen other recent ransomware incidents, including the University of Mississippi Medical Center in February 2026, which the Medusa group claimed with an $800,000 demand; no link between that incident and Vicksburg has been reported.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1490 Inhibit System Recovery
- T1657 Financial Theft

## Sources

- [Mississippi mayor says ransomware incident led city to shut down systems](https://therecord.media/vicksburg-mississippi-government-ransomware-attack)
- [City of Vicksburg hit by ransomware cyberattack, mayor says](https://www.wdam.com/2026/10/02/city-vicksburg-hit-by-ransomware-cyberattack-mayor-says/)
- [City of Vicksburg, Mississippi, shuts down computers after cyberattack](https://databreaches.net/2026/10/02/city-of-vicksburg-mississippi-shuts-down-computers-after-cyberattack/)
- [Ransomware Attack Shuts Down Vicksburg City Systems](https://www.isacchain.com/blog/ransomware-hits-vicksburg-mississippi-city-shuts-down-its-computers/)
- [Mississippi school districts targeted by ransomware attacks (2021 local context)](https://mississippitoday.org/2021/06/11/school-district-ransomware-attack-mississippi/)
- [Cybercriminals say they hacked UMMC, demand ransom](https://comparitech.com/news/cybercriminals-say-they-hacked-university-of-mississippi-medical-center-demand-ransom/)
- [Mississippi hospital system closes all clinics after ransomware attack](https://wtop.com/national/2026/02/mississippi-hospital-system-closes-all-clinics-after-ransomware-attack/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2862
