Delaware County got an update on the situation that caused a network challenge last month and learned that lessons learned from the hack six years ago came in handy this time.
On June 26, county officials became aware of “unauthorized activity,” resulting in them shutting down the government system, impacting phones and systems throughout county operations.
County Executive Director Barbara O’Malley shared some of the results of the investigation while giving an update to county council Wednesday.
“We recognize that there may be more questions and interest in the particulars of this event but we are being as informative as possible while maintaining security and minimizing risk by sharing specific details,” she said. “All county systems and operations have been restored nearly a month ago.”
She said the county discovered the incident when workers received alerts of anomalous network activity on June 26.
“We discovered the activity when our managed detection and response service began receiving alerts,” O’Malley said.
The decision was then made to take the system offline.
“We took immediate steps to confirm the integrity of our network and took the network offline until we could verify its security,” she said. “We also assessed the availability of secure backups so we could identify priorities for restoration.”
O’Malley credited the steps taken following the hacking six years ago for helping the county in this most recent situation.
“Thanks to efforts we implemented in response to the 2020 cybersecurity incident, the county had viable and secure backups we were able to utilize to restore our network and data once we confirmed our network was secure,” the executive director said.
Unlike the 2020 incident, this one was not a result of someone opening a fraudulent message.
“Our subsequent forensic investigation determined the cybercriminals responsible for the attack were able to gain remote access to the network on June 26, 2026 to commit the attack,” O’Malley said. “The investigation did not find any evidence of unauthorized access to the county’s email system, including no evidence of phishing emails.”

She said no further action has been detected.
“There has not been any evidence of unauthorized activity since the county secured its network on June 26,” she said.
O’Malley said what was accessed continues to be evaluated.
“Through the investigation, we determined the attackers were able to access data maintained within the network,” she said. “We are still reviewing to determine the types of data that were accessed and will notify any applicable individuals as required by Pennsylvania law if they had personal information involved in the attack.”
She noted the significant updates the county has made in the past six years.
“Those updates and steps were critical to our successful response to this recent incident,” O’Malley said. “They allowed the county to restore its network and data in a safe and secure manner that does not require us to rely on a decryption key or other outside tools, which reduced overall operational impact.”
She added that the county uses Endpoint Detection, managed by Crowdstrike.
“That tool alerted us to the intrusion in the first place,” O’Malley said
She also spoke about some of the steps being taken in response to this event.

“We coordinated with federal law enforcement for the investigation, engaged privacy counsel and cybersecurity specialists to assist in the investigation, reset all access credentials for all account holders across the entire network, rebuilt county systems and devices utilizing secure and uninfected backups and we continue to research any additional best practices and security measures that may be implemented,” she said.
The executive director praised county employees who maintained services to the public, even resorting to paper during the situation.
“Our county departments worked rapidly and creatively to ensure the continued delivery of services, as many services as possible during this attack,” O’Malley said. “We appreciate their efforts and we appreciate the residents’ patience as we found alternative ways to deliver services or in rare instances, services that did have to be delayed.”
O’Malley also noted that the county engaged in a cybersecurity specialist to determine the nature and scope of the attack and including risk to data.
“We continue our steadfast commitment to addressing the needs of our constituents and to ensure we have the best possible network infrastructure and security possible to ensure that we can provide effective services,” she said.
O’Malley also said that the county continues to make updates to its security network on a regular basis and in response to this incident.
“We are also committed to satisfying any legal notice or reporting obligations and working with our state and federal partners as necessary in response to this event,” she said.
“We wish to thank our residents and departments who’ve performed admirably during this outage and in particular, our IT staff for their tremendous efforts during this very difficult situation for the county and our residents,” O’Malley said.
Resident feedback
One resident, Kathy Buckley of Edgmont, said she would have liked more information about the incident.
“I don’t know if my Social Security’s out in nowhereland and someone’s using it,” she said. “I don’t know if my address, because I do pay taxes to Delaware County, if my address is out there … I’m getting a lot of spam mail and phone calls and I don’t know if it’s related or not related.”
The former poll worker said she wanted to know what departments were attacked and if her voting information remained intact.
“It’s a little too late,” Buckley said of the update, “and it didn’t include any details at all what happened, how it could’ve been prevented and what was released, what was attacked, where it went, what’s going on. It’s very scary.”
O’Malley responded to Buckley’s concerns.
“I do believe, again, that we want to be very cautious about what we share so as to not make ourselves vulnerable to additional attack or risk if we give more information about the incident,” she said. “It could potentially put us at risk for future incidents. I do hope people can understand that.”
O’Malley explained that the county is working with other experts to determine what is appropriate to release publicly about the incident.
“We are working very closely with our insurance company and privacy attorneys, cybersecurity attorneys and cybersecurity experts, who give us guidance about what is responsible to share and not to share,” she said. “I completely understand the curiosity. However, we are sharing what we are really able to share with the public.”
O’Malley emphasized that if any personal information was impacted, the county is bound by laws to notify individuals who were effected.
As the impacted information continues to be evaluated, the executive director added, “If notification is required, we will absolutely make those notifications as soon as it is identified that that type of information had been disclosed.
“I do appreciate the interest and the concern and desire for additional information and we will share what we can,” she added.
Click Here For The Original Source.
