North Carolina County Declines Ransom in Data Breach Affecting 128,000 People

Catawba County, North Carolina experienced a September 2025 cyber attack that potentially exposed personal information including Social Security numbers and medical records for approximately 128,000 individuals. North Carolina state law prohibits government entities from paying ransoms, so the county instead absorbed recovery costs through cybersecurity insurance and implemented enhanced security measures. The county offered affected residents complimentary credit monitoring and found no evidence that exposed data was subsequently misused.
Catawba County discovered the intrusion on September 19, 2025, though unauthorized access to its systems may have begun a week earlier. The breach compromised sensitive personal records spanning current and former residents, including identification numbers, financial details, and healthcare information for approximately 128,000 individuals. The county's response was shaped by state restrictions: North Carolina law explicitly bars government agencies from paying ransom demands. Instead, the county's cybersecurity insurance policy covered recovery expenses beyond a $50,000 deductible, while critical emergency systems remained uncompromised throughout the incident.
The incident illustrates potential tensions between cybersecurity vulnerabilities in local government infrastructure and legal constraints on incident response. Residents affected may face elevated identity theft risks despite no confirmed misuse thus far, potentially creating administrative burden as individuals monitor accounts and consider protective measures like credit freezes. The ransom prohibition, while preventing funds from reaching threat actors, shifts financial responsibility to insurance mechanisms and taxpayers. Such breaches could prompt broader discussions about cybersecurity funding adequacy for municipal operations and the effectiveness of current protective frameworks.