Merrimack County Cyberattack: What Happened?
September 2026
Merrimack County in New Hampshire, USA, recently experienced a network security incident that disrupted several county computer systems and temporarily affected government services.
The earliest documented impact occurred on August 25, 2026, when county dispatchers lost access to criminal-information data through New Hampshire's IMC system. The county publicly confirmed the incident on August 26 and began working with cybersecurity specialists to investigate the unauthorized activity.
What Happened?
Merrimack County dispatchers were unable to access important law-enforcement information, including:
Criminal records
Driving information
Active warrants
Nearly 20 law-enforcement departments rely on Merrimack County's dispatch services. Alternative procedures were used while access to the affected system was unavailable.
Despite the disruption, emergency call-taking and response operations continued.
The county also took some systems offline as a precaution while cybersecurity professionals investigated the incident.
Source: DysruptionHub
Register of Deeds Also Affected
The incident had another significant impact on the Merrimack County Register of Deeds.
Because of the network disruption, the office temporarily moved to paper-based procedures for property documents such as:
Deeds
Mortgages
Liens
Other property records
Electronic recording services were eventually restored, although staff had to work through a backlog created during the outage.
Was It Ransomware?
Ransomware has not been officially confirmed.
Merrimack County has described the event as a network security incident involving unauthorized activity. Officials have not publicly confirmed what malware or attack technique was used, whether files were encrypted, or whether a ransom was demanded.
Therefore, it is more accurate to describe the event as a cyberattack/network security incident rather than definitively calling it a ransomware attack.
Was Data Stolen?
A later threat-intelligence report said that a group known as Booba Project listed Merrimack County as a victim and claimed to have stolen approximately 3 GB of data.
However, this claim has not been independently confirmed by Merrimack County.
There is currently no public confirmation that Booba Project was responsible for the attack or that exactly 3 GB of data was stolen.
This distinction is important because claims published by threat actors on leak sites should not automatically be treated as verified breaches.
Timeline
August 25: County dispatchers experienced problems accessing criminal-information data.
August 26: Merrimack County publicly confirmed the network security incident and began its investigation.
Late August: Cybersecurity specialists investigated the unauthorized activity while affected systems remained offline or operated through alternative procedures.
September 14: County officials announced that the incident had been contained and that there was no active threat in the environment.
September 15: Electronic recording at the Register of Deeds resumed.
September 23: Reporting emerged about the Booba Project's claim of approximately 3 GB of stolen data.
What Remains Unknown?
Several important details have not been publicly disclosed, including:
How attackers initially gained access
Whether stolen credentials were involved
Whether a vulnerability was exploited
What malware, if any, was used
Whether sensitive information was accessed or stolen
Who was responsible for the intrusion
The county's ongoing investigation may provide more answers in the future.
Final Thoughts
The Merrimack County incident shows how a cyberattack against a government organization can affect everyday public services.
While emergency operations continued, law-enforcement information access and property-record processing were disrupted. The county responded by isolating affected systems, bringing in cybersecurity specialists and gradually restoring services.
For now, the cyber incident itself is confirmed, while claims about ransomware, the attackers and the alleged 3 GB data theft remain unverified.
Sources
Concord, NH Patch: County network security incident and official statements
https://new.patch.com/new-hampshire/concord-nh/county-hit-network-security-incident-officials-working-protect-personalDysruptionHub: Incident timeline and affected services
https://dysruptionhub.com/merrimack-county-network-security/DysruptionHub Incident Case File: Recovery information and Booba Project claim
https://dysruptionhub.com/incidents/profiles/merrimack-county-2026-01/SOCRadar: Reporting on the alleged 3 GB data theft
https://socradar.io/data-breach/the-merrimack-county-booba-project-ransomware-2026/
Note: The sources reviewed support August 25, 2026 as the earliest documented date of the incident; the previously mentioned August 20 date could not be verified.
Comments
Post a Comment