NEWS
Fort Smith’s Computer Attack Follows a Familiar City Script
Fort Smith’s computer attack is 26 days public, and 36,000 water accounts still have no word, while Mayor McGill promises a review.
Fort Smith’s computer attack has been public for 26 days, and Mayor George McGill now says the city should run a thorough review once the incident ends. The city still will not say whether personal and financial records of more than 36,000 water and sewer accounts were touched.
That sequence, card readers first, 911 declared safe, a long blackout, then a review promised after the fact, is how U.S. cities have handled these hits for years. The people waiting on McGill’s review are the account holders, the 1,032 city employees, and the vendors whose files sit on the same network.
The Card Readers Went Dark First
On Aug. 16 the city identified a security event impacting its computer network and said it had disrupted certain systems and services. The bulletin, sent at 7:57 p.m. CDT by communications director Josh Buchfink, said 911 dispatch and emergency response remained fully functional and that Fort Smith was working with federal law enforcement and cybersecurity specialists.
By Aug. 17, City Hall at 623 Garrison Avenue would take only cash and checks for utility bills, permits, and other in-person payments. The landfill scale house was in the same boat. Buchfink told residents to plan accordingly.
Ten days after the bulletin, some of that public-facing damage had been patched. On Aug. 26, Buchfink said credit and debit cards were again being accepted at City Hall, while crews were still working to restore those services at the landfill and district court. Chief information officer James Gentry, in an email that same week, said the investigation was ongoing and that the city could not answer questions.
THE FORT SMITH OUTAGE CLOCK
- August 16, 2026: City bulletin announces a network security event, with 911 still up and federal partners on the call.
- August 17, 2026: City Hall and the landfill stop taking cards and switch to cash and checks.
- August 25, 2026: Gentry declines a first round of written questions, saying the investigation is ongoing.
- August 26, 2026: Card payments return at City Hall; landfill and district court terminals remain in restoration.
- September 9, 2026: Written questions go to the mayor and the seven-member board about disclosure, service damage, and a public review.
Gentry’s line has not moved. In September the city said the event was still active, not a closed case in which the only job left was turning systems back on, and that sharing details could create more security risk or interfere with the work.
February’s Vendor Breach Was a Warning
The August outage did not arrive in a quiet year. In February the city found that ProPhoenix, the vendor behind jail, police, and fire software used with Sebastian County, had violated its contract and the FBI’s Criminal Justice Information Services security policy. Director of public safety Wes Milam said vendor access was pulled at once, and that the breach could threaten the River Valley Communications Center and the police department’s use of the Arkansas Crime Information Center.
Buchfink said there was no data loss in that incident. Milam described shoddy business practices, including people without the required clearances working on the system and someone in India trying to obtain credentials. The city is seeking a refund of $1.2 million and has said it will not renew. It is moving toward Central Square software, with a target of early 2027, and has been running without that vendor’s support since February, including CAD mobile software.
Eight days before the August bulletin, the same IT shop was already on a different alert. After water and sewer systems in at least 12 states reported cyberattacks, Buchfink said Fort Smith Water Resources and Information Technology had taken proactive measures and would not describe them. Gentry wrote that the city does not divulge specifics on critical infrastructure. An attack on that water system, the city noted then, would reach more than 150,000 metro users who depend on Fort Smith supply, not only the city accounts.
Director George Catsavis, answering September questions, said his biggest concern is the water system and that it is time for the administration to make a comment. Director Lee Kemp said police, fire, water, sewer, and other services continue, and that staff have worked extra hours without some of the technology they normally use. Those two statements can both be true. They still leave the public unable to tell which computers are up, which are in pieces, and whether the water-plant warning in early August and the city-network event on Aug. 16 share anything but a calendar.
36,000 Water Accounts Still Have No Answer
What the city has named, and then refused to discuss, is the data sitting on the disrupted network. Potentially at risk is personal and financial information of 1,032 employees and more than 36,000 residents and businesses with water and sewer accounts, plus vendor files. Officials will not say whether any of it was opened, copied, or taken.
WHOSE RECORDS ARE IN PLAY
- City employees: 1,032 staff files, including whatever payroll and identity data the city stores on the same network.
- Utility accounts: More than 36,000 water and sewer customers whose bills, payment cards, and service addresses live in city systems.
- Metro water users: More than 150,000 people in the Fort Smith region depend on the city’s water system, the figure the city used in its Aug. 8 warning, a wider group than the city account list.
- Vendors: Companies that have done business with the city, whose contracts and banking details the city will not discuss.
A blackout this complete also kills public argument. Local posts about the event were almost all reprints of the first bulletin, then silence, because there have been no confirmed facts to fight over. Residents cannot pressure a council over a ransom demand the city will not confirm, or over a leak the city will not rule out.
WHAT WE KNOW
- The start date: The city made the event public on Aug. 16 and said 911 never went down.
- The first outage: In-person card payments failed at City Hall and the landfill on Aug. 17, then returned at City Hall on Aug. 26.
- The posture: Gentry and the September city statement both treat the incident as still active, with federal law enforcement and cybersecurity specialists involved.
WHAT IS UNCONFIRMED
- The method: The city has not said whether ransomware, a payment demand, or another form of intrusion is involved.
- The data: No official has said whether employee, resident, or vendor files were accessed or removed.
- The map: Which systems remain fully or partly offline, why recovery is still running, and when service returns to normal are all unanswered.
Kemp said he understands the public’s desire for information and that the board must be careful not to speculate or release anything that could interfere with the response. Director Christina Catsavis said she has been advised not to speak to specifics, and that the guidance is coming from the professionals handling the response, not from a wish to dodge accountability. Director Neal Martin said the administration is sharing information with the board and being cautious about what leaves the building. Directors André Good, Jarred Rego, and Kevin Settle did not answer the September questions.
How Long Other Cities Kept Customers Waiting
Fort Smith’s phrasing, a network security event, 911 untouched, cards dead at the counter, is not local color. Cities of this size lose payment terminals first because those systems sit on the same office network as billing, permits, and email. Emergency radio and dispatch are often segmented, which is why the 911 reassurance arrives in the first paragraph of so many municipal bulletins.
Comparitech researchers logged 187 ransomware attacks on government entities in the first half of 2026, an average of one a day, with 89 confirmed by the targets. The United States accounted for 58 of those attacks, a 23 percent drop from 75 in the second half of 2025, and governments remain useful targets because encryption stops services and the data holdings are large enough to support a second ransom. Across confirmed cases in that period, it takes government agencies about four months to notify victims of related data breaches.
WHEN OTHER CITIES TOLD PEOPLE
| City | When it became public | What was confirmed | Notices sent |
|---|---|---|---|
| Fort Smith, Ark. | Aug. 16, 2026 | Network event, card payments hit, 911 up, still active as of September | None announced |
| Suffolk, Va. | February 2026 | Data taken even though ransomware was stopped before it launched | 157,725 people |
| Middletown, Ohio | July 2025 | Later treated as a data breach with delayed letters | 123,791 people |
Suffolk’s notices went out after Cloak claimed 2.5 TB of data. Middletown’s letters arrived many months after the breach month on the file. If Fort Smith eventually finds that unencrypted personal information left the building, that four-month average is the wait the 36,000 accounts should budget for, not McGill’s review hearing.
CISA, citing Verizon’s 2025 Data Breach Investigations Report, says ransomware figured into 44 percent of the breaches Verizon investigated, and phishing figured into 43 percent of the public-sector breaches in that set. The federal share accurate information with the public step sits on the same checklist as isolating infected machines and calling the FBI. Fort Smith has done the isolation language. It has not done the public half beyond the first bulletin, the card-payment notes, and the September refusal.
Arkansas Law Starts After Harm Is Found
Arkansas does not give cities a 30-day shot clock. Under the Personal Information Protection Act, a person or business that owns computerized personal information must disclose a breach to any Arkansas resident whose unencrypted data was, or is reasonably believed to have been, acquired by an unauthorized person, and where there is a reasonable likelihood of harm. The disclosure must be made in the most expedient time and manner possible and without unreasonable delay, with room to investigate scope and restore the system.
If more than 1,000 people are in the affected class, the holder must also notify the Arkansas Attorney General at the same time it notifies residents, or within 45 days after it determines a reasonable likelihood of harm, whichever comes first. Notification may be delayed if law enforcement finds that notice would impede a criminal investigation. Encrypted data, with the key intact, sits in a safe harbor. Personal information here means a name plus a Social Security number, driver’s license number, financial account data with access codes, medical information, or biometric data.
The 1,032 employees alone would clear the 1,000-person Attorney General trigger if a breach is found. The water-account list would clear it many times over. None of that clock starts until the city determines that unencrypted personal information was acquired and that harm is reasonably likely. A still-active incident, plus a law-enforcement delay, can legally look like this for a long time. It does not require the city to say which systems are down, or to say that no data left.
CISA tells state and local governments to report any cyber incident to CISA even when they already have other reporting duties, and not to wait for a finished investigation. Fort Smith has said it is working with federal law enforcement and cybersecurity specialists. It has not said whether that circle includes CISA, the FBI field office, or a private firm on a cyber-insurance panel, and the September statement treats public detail as a risk in itself.
McGill Wants a Review With No Date Attached
The elected officials who answered want an accounting after the incident is closed. They do not agree, in public, on how hard to push while it is open. George Catsavis wants the administration to speak now, at least about water. Kemp wants an appropriate public accounting and praised staff, including Gentry’s IT team. Martin said there definitely should be a full and public accounting. Christina Catsavis said she will push for a clear and honest review because the public has a right to know.
Once the immediate incident is resolved and the appropriate investigations are complete, I believe the city should conduct a thorough review of what happened, how it happened, what systems were affected, what information may have been exposed, and how the city responded. The public deserves accountability. That includes determining whether weaknesses in our systems, policies, procedures, training, technology, or oversight contributed to the incident. I would also support a clear plan for what needs to change going forward. That could include an independent cybersecurity assessment, additional safeguards, employee training, stronger backup and recovery systems, regular testing, and appropriate ongoing monitoring.
George McGill, Mayor of Fort Smith, written response
That is a real list, and it is also a list with no calendar. McGill tied every item to the end of the incident and the end of the investigations. The city’s own September note said the event was still active.
WHAT MCGILL PUT ON THE TABLE
- The facts: What happened, how it happened, which systems were affected, what information may have been exposed, and how the city responded.
- The faults: Whether weaknesses in systems, policies, procedures, training, technology, or oversight helped the incident along.
- The fixes: An independent cybersecurity assessment, more safeguards, staff training, stronger backups and recovery, regular testing, and ongoing monitoring.
Christina Catsavis used a shorter version of the same demand, a clear account of what happened, why, what was affected, and what will change so it does not happen again. Kemp’s caution about speculation is the reason none of those questions have answers while Gentry’s investigation tag is still on the file. The February vendor breach already showed the city can describe a security failure, name the contractor, state that data was not lost, and put a dollar figure on the unwind, when it decides the event is over.
Until that happens here, the 36,000 accounts have the city’s first bulletin, a two-week stretch of cash-only counters, and a promise that a thorough review will come after the investigations end. The city said it will provide more information as soon as it can do so safely and responsibly. McGill’s review waits on that day, and so do the letters Arkansas law would require if the harm finding ever arrives.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
