Lakescurrent Daily Briefing English
Lakescurrent.com Lakescurrent Daily Briefing
Blog Business Local Politics Tech World

St. Paul Cyber Attack 2025: What Happened, Updates

Jackson Oliver Mercer Bennett • 2026-04-24 • Reviewed by Ethan Collins

When St. Paul, Minnesota discovered suspicious activity in its city networks in late July 2025, the chain of events that followed included a full-scale ransomware incident that forced the capital city to shut down digital services, declare a state of emergency, and call in the Minnesota National Guard. The Interlock ransomware group claimed responsibility, posting 43 GB of stolen city data online, yet St. Paul refused to pay—relying instead on clean backups and federal partnerships to bring systems back online. The city had Smart Cities Dive report that 911 and emergency services never went down, and by August 29 most public systems were operational again.

Date: August 2025 · Type: Ransomware (Interlock) · Affected: St. Paul city systems · Response: National Guard deployed · Status: Systems back online (Aug 29)

Quick snapshot

1Confirmed facts
2What’s unclear
  • Exact breach entry point
  • Total financial cost
  • Full data breach scope
3Timeline signal
  • July 25: Activity detected
  • July 28: Network shutdown
  • Aug 11: Data posted online
4What’s next
  • Forensic review ongoing
  • System hardening underway
  • Legal notifications pending

Key facts about the St. Paul incident emerge from official records and incident documentation.

Field Value
Location Saint Paul, Minnesota
Attack Type Ransomware
Confirmed Date 2025
Agencies Involved FBI, CISA, National Guard
Recovery Systems online by Aug 29

What happened in the St. Paul cyber attack?

The St. Paul cyberattack was a confirmed ransomware incident targeting the Minnesota capital city’s government systems. Suspicious activity was detected on July 25, 2025, and the city implemented a full network shutdown on July 28 to contain the threat (Smart Cities Dive). Mayor Melvin Carter described the incident as “a deliberate, coordinated digital attack by a sophisticated external actor” (SecureMac). The Interlock ransomware group claimed responsibility and posted 43 GB of stolen data on August 11, 2025 (The Register). The city refused to pay the ransom on advice from FBI and National Guard (GovTech). By October 2025, over 75% of St. Paul’s digital systems were restored (KSTP). The stolen data primarily came from the Parks and Recreation Department’s network drive (Smart Cities Dive). Interlock claimed to have stolen over 66,000 files including passports and employee records (The Register).

Initial breach details

The attack hit St. Paul’s systems in late July 2025. Suspicious activity was detected on July 25, 2025 (Wikipedia), and CISA and FBI had already issued a joint advisory on Interlock activity on July 22, 2025—three days before the breach was detected (SecureMac). The stolen data represented 43 GB out of the city’s 153 TB total (GovTech). What remains unclear is the exact entry vector Interlock used and which specific department was the initial breach point.

Systems impacted

City services disrupted included payment portals, library networks, municipal Wi-Fi, and online billing (The Register). Operation Secure St. Paul involved password resets for over 3,500 employees starting August 10, 2025 (GovTech). Mayor Carter joked that “over 3,500 St. Paul city employees now have absolutely the longest passwords of their entire lives” (Urban Cyber Defense MIT). The good news: 911 and emergency services remained operational throughout the incident because the city had clean backups from July 25, 2025 unaffected by the hack (GovTech). Payroll was processed manually with checks issued by August 8, 2025 (GovTech).

The upshot

St. Paul’s clean backup strategy from July 25 meant no service disruption for 911 callers and a manual fallback for payroll. That calculus—investing in offline backups before a crisis—kept lives and finances running while recovery teams rebuilt encrypted systems.

TL;DR: St. Paul absorbed a major ransomware attack and kept emergency services running by relying on clean backups made before the breach.

Did St. Paul, Minnesota have a cyber attack?

Yes. The cyberattack on St. Paul, Minnesota began with suspicious activity detected on July 25, 2025 (Wikipedia). Mayor Melvin Carter declared a local state of emergency on July 29, 2025 (Wikipedia), and Governor Tim Walz activated the Minnesota National Guard’s Cyber Protection Team on July 29, 2025 (Smart Cities Dive). The city collaborated with FBI, CISA, and Minnesota National Guard from detection onward (Smart Cities Dive). The forensic review of exposed data is ongoing, with notifications proceeding per legal requirements (City of St. Paul).

Confirmation from officials

The attack was confirmed by city officials who described it as a ransomware incident requiring multi-agency response. St. Paul had clean backups from July 25, 2025, and recovery efforts prioritized critical systems first (Smart Cities Dive). No widespread problems occurred due to early detection (GovTech). Full cost of the attack has not been publicly disclosed as of October 2025 (KSTP).

Timeline of events

Key dates from the St. Paul incident:

Date Event
July 25, 2025 Suspicious activity detected
July 28, 2025 Full network shutdown
July 29, 2025 Local emergency declared; National Guard activated
August 10, 2025 Password reset operation starts
August 11, 2025 Data leak by Interlock
August 25, 2025 Email with Ramsey County restored
August 29, 2025 Systems come back online
October 2025 75% systems restored

The pattern: St. Paul detected early, isolated fast, and brought critical services back within weeks while completing the bulk of restoration by October 2025.

TL;DR: St. Paul declared an emergency and activated the National Guard on July 29, 2025, confirming a coordinated external attack.

Did Minnesota have a cyber attack?

St. Paul was the primary cyberattack target in Minnesota during this period, but not the only one. St. Paul was one of six Minnesota government bodies hit by ransomware in the last year (GovTech). The National Guard was deployed to Winona for related incidents, and Governor Tim Walz activated the Minnesota National Guard’s Cyber Protection Team on July 29, 2025 for St. Paul specifically (Smart Cities Dive). Global ransomware attacks on governments were up 65% in the first half of 2025 (ASIS International), making Minnesota part of a nationwide escalation in municipal attacks.

St. Paul specifics

St. Paul suffered the most visible and disruptive attack in the state’s recent ransomware history. Interlock targeted healthcare entities like DaVita and Kettering Health prior to St. Paul (SecureMac), suggesting the group casts wide nets across sectors. Post-attack, the city accelerated rollout of the PAULIE permitting system in September 2025 (Route Fifty). The city invested in phishing drills and tabletop exercises post-attack (Urban Cyber Defense MIT).

Related incidents

The St. Paul attack fits a broader pattern of cities refusing to pay ransoms. Like Atlanta (2018) and Baltimore, St. Paul refused to pay. Those prior cities faced combined costs exceeding $17 million (GovTech). The tradeoff: non-payment means expensive manual workarounds and slower recovery, but avoids funding criminal operations and sets no precedent for future demands.

Why this matters

Six Minnesota government bodies in one year is not coincidence—it’s a pattern. Local governments share infrastructure, vendors, and security gaps, meaning one successful breach often signals vulnerabilities across the state. The question is whether Minnesota treats this as a statewide crisis or six isolated incidents.

TL;DR: St. Paul joins five other Minnesota government bodies hit by ransomware in the same year, signaling systemic vulnerabilities across the state.

What is the St. Paul cyber attack update?

Systems came back online August 29, 2025, and by October 2025 over 75% of St. Paul’s digital systems were restored (KSTP). Email connection with Ramsey County was restored on August 25, 2025 (GovTech). The official St. Paul Digital Security Incident Info Hub went live August 27, 2025 (City of St. Paul). The forensic review of exposed data is ongoing, with notifications proceeding per legal requirements. Full cost of the attack has not been publicly disclosed as of October 2025.

Recovery progress

The city restored systems in phases, prioritizing critical infrastructure. Recovery efforts prioritized critical systems first (Smart Cities Dive). Payroll was processed manually with checks issued by August 8, 2025 (GovTech). Operation Secure St. Paul involved password resets for over 3,500 employees starting August 10, 2025. Post-attack, the city accelerated rollout of the PAULIE permitting system in September 2025 (Route Fifty).

Systems online status

What remains unclear: whether all systems were fully restored as of 2025 or early 2026, the total financial cost, and the complete scope of data exposure. The forensic review continues, and legal notifications are pending. The city has not disclosed the exact ransom amount demanded, if any.

The trade-off

St. Paul paid no ransom but incurred weeks of manual operations, emergency response costs, and ongoing forensic work. The city saved millions by not paying but is still tallying the true cost of response and system hardening. For other cities: the ransom is only the starting point of expenses.

TL;DR: St. Paul recovered most systems by October 2025 but has not disclosed the total cost of its months-long response and recovery effort. For more information on ongoing conflicts, you can refer to Russo-Ukrainian War Updates.

Who is behind the St. Paul cyber attack?

The Interlock ransomware group claimed responsibility for the attack and posted 43 GB of stolen data on August 11, 2025 (The Register). Interlock has been active since September 2024 using double-extortion tactics (The Register). The group described itself as “a relentless collective that exposes the recklessness of companies failing to protect their most critical assets” (The Register). Mayor Carter called Interlock “a sophisticated and money-driven ransomware-as-a-service organization” (Wikipedia). Interlock may have infiltrated systems as early as July 20, 2025 per threat intelligence (SecureMac).

Group claims

Interlock claimed to have stolen over 66,000 files including passports and employee records from the Parks and Recreation Department’s network drive (The Register). The stolen data represented 43 GB out of the city’s 153 TB total (GovTech). The group had previously targeted healthcare entities like DaVita and Kettering Health (SecureMac).

Investigation details

The city collaborated with FBI, CISA, and Minnesota National Guard from detection onward (Smart Cities Dive). FBI advised against ransom payment, and the city refused to pay (GovTech). The forensic review of exposed data is ongoing, with notifications proceeding per legal requirements (City of St. Paul). What remains unclear: legal actions against Interlock and whether the group’s post-St. Paul operations have been disrupted.

TL;DR: Interlock ransomware group executed the attack, posted stolen city data online, and remains under investigation as FBI and CISA continue their forensic analysis.

It was a deliberate, coordinated digital attack by a sophisticated external actor.

— Mayor Melvin Carter (SecureMac)

A relentless collective that exposes the recklessness of companies failing to protect their most critical assets.

— Interlock ransomware group (The Register)

Confirmed facts

  • Ransomware attack confirmed
  • Interlock claimed responsibility
  • 43 GB data posted online
  • FBI advised against ransom payment
  • National Guard deployed
  • Systems restored without payment
  • Forensic review ongoing

What’s unclear

  • Exact breach entry point
  • Total financial cost
  • Full data breach extent
  • Ransom amount demanded
  • Resident data notifications pending
  • Legal actions against Interlock

The pattern is clear: ransomware groups like Interlock target municipalities with outdated systems, demand payment, and leak data when refused. The implication is that more cities will face this playbook unless federal agencies and local governments coordinate preventive investments before the next attack.

Additional sources

kstp.com, safeaeon.com

The ransomware disrupted core city operations in late July 2025, prompting National Guard involvement as chronicled in the St. Paul cyber attack timeline.

Frequently asked questions

What systems were hit in the St. Paul cyber attack?

City services disrupted included payment portals, library networks, municipal Wi-Fi, and online billing. The stolen data came primarily from the Parks and Recreation Department’s network drive. Emergency services including 911 remained operational throughout.

How long did the St. Paul cyber attack last?

Suspicious activity was detected July 25, 2025, with a full network shutdown on July 28. Systems came back online August 29, 2025. By October 2025, over 75% of systems were restored.

Was resident data compromised?

Interlock claimed to have stolen over 66,000 files including passports and employee records. The forensic review of exposed data is ongoing, with notifications proceeding per legal requirements. Residents should monitor official city communications for data exposure notices.

What precautions for St. Paul residents?

Monitor financial statements for suspicious activity. Watch for official notifications from the city regarding data exposure. Consider credit monitoring if affected by the breach.

Are there similarities to other city attacks?

St. Paul joins Atlanta (2018) and Baltimore in refusing to pay ransoms. Those cities faced combined costs exceeding $17 million. Global ransomware attacks on governments were up 65% in the first half of 2025.

When was the St. Paul cyber attack declared?

Mayor Melvin Carter declared a local state of emergency on July 29, 2025. Governor Tim Walz activated the Minnesota National Guard’s Cyber Protection Team the same day.

For other city governments, the lesson is straightforward: pre-built federal partnerships, offline backups, and a no-ransom policy are not luxuries—they are the minimum viable defense in an era when ransomware groups are increasingly targeting municipalities.

St. Paul’s decision to invest in clean backups before the breach meant emergency services never wavered. That practical choice—funded through normal IT budgets rather than crisis spending—kept the city functional while recovery teams worked through the aftermath.

Residents can find official updates at the City of St. Paul Digital Security Incident Info Hub. For related context on government cybersecurity, see our guide on W-9 Form 2025 filing procedures and Department of Motor Vehicles digital services.



Jackson Oliver Mercer Bennett

About the author

Jackson Oliver Mercer Bennett

Coverage is updated through the day with transparent source checks.