
The City of Circleville recently identified a cybersecurity incident affecting portions of the City’s
technology environment. Upon detection, the City and its technology provider immediately
initiated containment and incident-response procedures, including isolating systems, investigating
potentially affected devices, and beginning recovery operations.
The incident involved ransomware activity. The City did not pay a ransom.
City operations have been restored. Systems identified as affected were rebuilt from clean
environments or recovered through established recovery procedures, and systems were reviewed
before being returned to service.
The City’s investigation and post-incident security review remain ongoing. The City has
communicated and coordinated with appropriate governmental and law-enforcement entities
regarding the incident consistent with applicable requirements under the Ohio Revised Code. The
City will continue to provide notifications and information to appropriate authorities as required.
At this time, the City is not aware of evidence establishing that sensitive information was exfiltrated
as part of the incident. Because the investigation remains ongoing, the City will continue evaluating
available evidence and will take any additional notification or protective actions required if new
information is identified.
The City takes the security of its systems and information seriously. Prior to this incident, the City
and its technology provider had cybersecurity protections in place, and additional security
enhancements were already being evaluated. The City is continuing to review and strengthen its
cybersecurity controls following the incident.
The City appreciates the efforts of its employees, technology personnel, law-enforcement
partners, and other agencies involved in the response and recovery.
To protect the security of City systems and the integrity of the continuing investigation, the City will
not publicly disclose detailed information regarding network architecture, security configurations,
investigative methods, specific defensive technologies, or other information that could increase
cybersecurity risk.

The City will provide additional information when appropriate as the investigation and post-
incident review continue.







