Denverinsight Breaking Wire English
DenverInsight.com Denverinsight Breaking Wire
Blog Business Local Politics Tech World

2025 St. Paul Cyber Attack: Timeline, Cost, and Lessons Learned

Liam James Mercer Reed • 2026-07-25 • Reviewed by Daniel Mercer

When a city’s digital backbone goes dark, the ripple effects are immediate—citizens can’t pay bills, permits stall, and employee email goes silent. That’s what happened in Saint Paul, Minnesota, starting July 25, 2025, when city cybersecurity systems detected unauthorized activity on a critical backup server. The ransomware attack forced a complete network shutdown, cost an estimated $2.5 million, and took months to unwind. This article traces the timeline, the response, and the lessons that other municipalities can draw from the ordeal.

Attack type: Ransomware ·
Start date: July 25, 2025 ·
City affected: Saint Paul, Minnesota ·
Estimated cost: $2.5 million ·
Recovery milestone: Over 75% of systems restored by October 2025

Quick snapshot

1Confirmed facts
2What’s unclear
  • Identity of the ransomware group behind the attack (unconfirmed)
  • Whether any sensitive data was exfiltrated (unconfirmed)
  • Exact ransom demand (if any was made) (unconfirmed)
  • Whether compromised accounts were the root cause (unconfirmed)
3Timeline signal
  • Detection: July 25, 2025 · Network shutdown: July 28 · Public confirmation: July 29 (KSTP)
  • Data leak: August 11, 2025 · Services restart: late August · 75% restored: October 22 (KSTP)
  • Cost disclosed: March 2026 (KSTP)
4What’s next
  • City aims for 100% system restoration; final cost still pending
  • FBI and CISA continue investigation
  • Other cities expected to review their backup server security

Six key facts capture the essentials of the 2025 St. Paul cyberattack—three proven, three still under investigation.

Attribute Value
City Saint Paul, Minnesota
Attack start date July 25, 2025
Type of attack Ransomware
Estimated cost $2.5 million
Systems restored by October 2025 >75%
Investigation status Ongoing, no public attribution

What happened in the St. Paul cyber attack?

Initial detection and response

  • At 2:37 p.m. local time on July 25, 2025, the city’s cybersecurity systems flagged suspicious activity involving compromised accounts tied to a critical backup server (City of Saint Paul).
  • IT staff immediately deactivated the compromised accounts and isolated the affected servers (City of Saint Paul).
  • The city brought in a nationally recognized incident response firm on July 26 to contain the threat and begin forensic investigation (City of Saint Paul).

Systems affected and shutdown

  • On July 27, the city disabled VPN access for most employees to cut off attacker movement across the network (City of Saint Paul).
  • The following day, July 28, Saint Paul pulled the plug on the broader network—essentially a “lights out” move to eradicate the attacker from city systems (City of Saint Paul).
  • City services ranging from permit processing to employee email went offline. The mayor requested emergency support from the Minnesota National Guard cybersecurity team (City of St. Paul news conference).

Official confirmation and public notification

  • On July 29, city officials held a press conference confirming a ransomware attack and stating publicly that the city would not pay the ransom (City of Saint Paul).
  • The city launched a public Cyber Incident Info Hub to keep residents informed.
  • On August 11, attackers posted a set of stolen data on their leak site after the city refused to pay (City of Saint Paul).
Bottom line: Saint Paul chose a full network isolation—disruptive but decisive—over paying a ransom, betting that containment and rebuild would protect residents’ data in the long run.

The pattern: This approach, while effective, required months of recovery.

Who was responsible for the St. Paul cyber attack?

Attribution efforts by law enforcement

  • The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) are leading the investigation (CISA).
  • As of early 2026, no specific group has been publicly named (City of Saint Paul).

Possible ransomware groups and known tactics

  • Forensic analysis indicates the use of a known ransomware variant, though the exact strain has not been disclosed to the public (GovTech).
  • The attackers gained initial access via compromised accounts on a critical backup server, a technique common to several active ransomware operations (City of Saint Paul).

Role of federal agencies

  • CISA has provided technical assistance and threat intelligence throughout the recovery (CISA).
  • The FBI’s cyber division is pursuing attribution, but investigations of this kind typically take months or longer (FBI).

The implication: Without a public attribution, other cities can’t yet identify the specific threat group, but the TTPs (tactics, techniques, and procedures) are well-documented—making this a textbook case of how ransomware operators target municipal networks today.

How did St. Paul respond to the ransomware attack?

Immediate containment and isolation

  • Within 72 hours of detection, the city had deactivated compromised accounts, isolated affected servers, and engaged an external incident response firm (City of Saint Paul).
  • By July 28, the entire city network was taken offline—a drastic step that prevented the ransomware from spreading but also halted most digital operations (City of Saint Paul).

Restoration of systems over several weeks

  • The city began a mass password reset for employees; by August 13 more than 2,000 passwords had been changed (KSTP report).
  • Microsoft email and cloud storage were declared secure again by August 20 (GovTech).
  • Public internet at city facilities was restored in September (Star Tribune).
  • As of October 22, 2025, about 75% of all city systems had been brought back online (KSTP).

Cost of response and recovery efforts

  • The city reported in March 2026 that the attack had cost $2.5 million (KSTP).
  • The final cost figure will only be released once the city reaches 100% recovery (KSTP).
The trade-off

Saint Paul’s leaders chose a walled-off recovery over a quick ransom payment. The consequence: a multi-month restoration that left residents without digital services, but the city avoided rewarding attackers and likely prevented wider data loss.

The implication: The cost of disruption was high, but the city retained its integrity and data control.

What did we learn from the St. Paul attack?

Lessons for municipal cybersecurity

  • The attack exploited compromised accounts tied to a critical backup server—a vector that could have been neutralized with stricter access controls and multi-factor authentication (City of Saint Paul).
  • Early detection by the city’s monitoring systems was effective, but the attacker still managed to exfiltrate data before being contained (City of Saint Paul).

For more on securing digital services, see our guide on Illinois Secretary of State Services, Appointments & DMV Guide.

Importance of regular backups and segmentation

  • The restoration took more than a month, underscoring the need for resilient, air-gapped backups (GovTech).
  • Network segmentation—keeping critical servers separate from everyday employee access—could have reduced the blast radius (CISA guidance).

Need for incident response planning

  • Saint Paul’s pre-existing incident response playbook helped IT staff act quickly in the first hours (City of Saint Paul).
  • Yet the extended downtime showed that even a well-prepared city can struggle with the complexity of rebuilding an entire digital environment from scratch.
Why this matters

For the hundreds of U.S. cities running on tight IT budgets, Saint Paul is a real-world cost schedule: $2.5 million and months of downtime. The choice is between investing in resilient infrastructure beforehand or paying more later.

The pattern: The attack serves as a blueprint for what municipal preparedness should look like.

How does the St. Paul attack compare to other major cyberattacks?

Similarities with WannaCry and other ransomware incidents

  • The 2017 WannaCry outbreak infected 230,000 computers in 150 countries, but Saint Paul’s attack was localized to a single city’s network (BBC).
  • Both attacks used a worm-like capability to spread laterally—though Saint Paul’s shutdown stopped the spread in its tracks.

Comparison with attacks on airports and critical infrastructure

  • Recent ransomware incidents at Bristol Airport (UK) and Porto Airport (Portugal) also forced operational shutdowns and cost millions to resolve (Eurocontrol).
  • Unlike airport attacks that directly threaten travel, a municipal ransomware incident disrupts daily civic life—permits, payments, records, communications.

Scale and impact relative to historical cyberattacks

  • Saint Paul’s $2.5 million price tag places it among the costlier municipal ransomware events in the U.S., comparable to Atlanta’s 2018 cyberattack and Baltimore’s 2019 incident (ZDNet).
  • But the recovery timeline—still ongoing in early 2026—may eventually push the total cost higher than initially reported.

The pattern: Municipal ransomware is not new, but the stakes are rising. What was once a disruption of email is now a full-on civic shutdown with million-dollar recovery tabs. Understanding the impact of digital disruptions is key, as seen in our article on Twitter Rate Limit Exceeded: How to Fix It & What It Means.

Confirmed facts

  • Attack started on July 25, 2025.
  • Ransomware was used.
  • City spent $2.5 million on recovery.
  • Over 75% of systems restored by October 2025.

What’s unclear

  • Identity of the ransomware group.
  • Whether any data was exfiltrated.
  • Exact ransom demand (if any).
  • Full extent of data loss.
  • Whether compromised accounts were the root cause.

“On July 25, 2025, the City’s cybersecurity systems detected suspicious activity involving compromised accounts tied to a critical backup server.”

— City of Saint Paul, official Cyber Incident Info Hub (Source)

“The ransomware attack cost the city an estimated $2.5 million.”

— KSTP report, March 2026 (Source)

The stakes for Saint Paul are not just about ones and zeros—they’re about whether a city can maintain its contract with citizens when its digital nervous system fails. For finance directors in cities across Minnesota, the implication is clear: either invest in resilient backup infrastructure and incident response training now, or face a $2.5 million emergency and months of angry resident calls later.

For a more detailed timeline of the St. Paul cyber attack, see detailed timeline of the St. Paul cyber attack.

Frequently asked questions

What type of ransomware hit St. Paul?

The specific ransomware variant has not been publicly identified. The city has confirmed it was a ransomware attack but has not disclosed the strain used (City of Saint Paul).

How long were city systems down?

The network was shut down on July 28, 2025. Services began returning in late August, but as of October 2025 only 75% of systems had been restored. Full recovery is still ongoing (KSTP).

Did the attack affect 911 or emergency services?

The city has not reported any disruption to 911 or emergency dispatch services. The shutdown primarily affected administrative and back-office systems (City of Saint Paul).

Was any personal data of residents stolen?

On August 11, 2025, a data set was exposed on the attacker’s leak site. The city has not disclosed the contents of that data. An investigation is ongoing (City of Saint Paul).

How can residents verify the safety of city services?

Residents can check the official Cyber Incident Info Hub for updates on system status and security measures.

Is the St. Paul attack connected to other recent ransomware attacks?

Investigators have not confirmed any connection to other incidents. The TTPs used are similar to those of multiple active ransomware groups, but attribution remains pending (FBI).

What steps has the city taken to prevent future attacks?

Saint Paul has implemented enhanced monitoring, restricted administrative accounts, and is reviewing its backup architecture. The city has also engaged external cybersecurity consultants for ongoing hardening (City of Saint Paul).



Liam James Mercer Reed

About the author

Liam James Mercer Reed

Our desk combines breaking updates with clear and practical explainers.