Skip to content
Ransomware Targets Backup Systems: Merrimack County Avoids Ransom Payment

Ransomware Targets Backup Systems: Merrimack County Avoids Ransom Payment

First seen 7 Oct 2026, 17:28 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 18:57 UTC
  • •Merrimack County avoided a ransom payment due to effective backup systems.
  • •The cyberattack occurred in late August 2026, impacting several county services.
  • •Details of the attack remain limited, with no confirmed use of AI or phishing.

Merrimack County experienced a ransomware cyberattack in late August 2026 that disrupted services. County Administrator Ross Cunningham confirmed that their backup systems allowed them to restore operations without paying a ransom. The specific details of the attack remain limited, and there is no indication of AI or phishing involvement. The incident highlights the importance of maintaining robust backup systems to mitigate ransomware threats. The county's Register of Deeds office was notably affected, unable to accept electronic submissions for weeks. The attack's vector and the identity of the threat actors have not been disclosed, and the investigation is ongoing.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-xx
Ransomware cyberattack on Merrimack County
A cyber incident disrupted services for several days, but backups allowed recovery without ransom payment.
ConcordMonitor

More articles in this cluster (6)

Following this threat?

Track BlackCat and Change Healthcare in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What happened to Merrimack County?
Merrimack County experienced a ransomware cyberattack that disrupted services but did not result in a ransom payment due to effective backup systems.
How did the county avoid paying ransom?
The county maintained robust backup systems that allowed them to restore operations safely without paying the attackers.
What details are known about the attack?
Specific details about the attack vector and threat actors remain undisclosed, and the investigation is ongoing.