Key Takeaways
- University City experienced a month‑long cyberattack that disabled online services such as bill payments and building‑permit processing.
- City officials initially blamed “server issues” before confirming the outage resulted from malicious intent.
- No evidence has been found that residents’ personal information was accessed; the attack was halted before data could be exfiltrated.
- In response, staff reverted to manual, in‑person processes for payments and permits, causing inconvenience for residents.
- Residents have criticized the city’s communication as poor and insufficient, raising suspicions about undisclosed problems.
- The incident fits a regional pattern of cyberattacks on Missouri municipalities, including Kansas City (May 2024) and St. Joseph (June 2025).
- Prior to the attack, University City had already budgeted $170,000 to move its accounting software to the cloud and had contracted Tyler Technologies for hosting.
- The city’s proposed fiscal 2027 budget includes upgrades to aging network infrastructure across city hall, police, remote offices, and the municipal parking garage.
- Restoration is proceeding in phases with a focus on security, but officials have not yet announced a date for full service recovery.
- The episode underscores the need for transparent public communication, proactive cybersecurity measures, and resilient IT architecture for local governments.
Overview of the Cyberattack and Its Immediate Effects
University City’s online services began to fail in the spring, leaving residents unable to pay utility bills, parking tickets, or submit building‑permit applications through the city’s website. The disruption persisted for roughly a month, affecting all credit and debit‑card transactions with the municipality. While essential public‑safety operations—police, fire, and emergency services—continued without interruption, the loss of digital access forced city staff to handle many routine tasks manually. The outage was noticeable enough that long‑time resident Beth Herbster had to visit City Hall in person to pay her refuse bill after the online portal repeatedly returned errors.
City’s Initial Communication and Shift in Narrative
For several weeks, University City officials described the problem generically as “server issues,” posting a brief “News Flash” on the city website and Facebook page on June 17 that apologized for the inconvenience and noted that the IT team was working to restore services. A follow‑up Facebook update on June 22 offered no further detail, leaving the public uncertain about the root cause. When the St. Louis Post‑Dispatch inquired on July 15 whether the outage stemmed from a cyberattack, the city referred back to its earlier statements, maintaining the server‑issue explanation. Only later did communications manager Jared Jones acknowledge that the disruption was the result of malicious intent.
Statements from Communications Manager Jared Jones
In an email to the Post‑Dispatch, Jones clarified that “the cyberattack disrupted network connections and prevented access to several essential city systems and online services.” He said that once the malicious activity was identified, the city collaborated with its technology and cybersecurity partners to stop the attack and begin rebuilding the affected systems. Jones emphasized that, as of Wednesday, investigators had found no evidence that residents’ personal information had been accessed, noting that the malicious activity was stopped before any data could be taken. He also confirmed that restoration was underway in phases to maintain security, though a definitive date for full recovery had not yet been set.
Impact on Residents and Local Businesses
The shift to manual processes created noticeable hardships for residents accustomed to online convenience. Beth Herbster, a real‑estate agent who has lived in University City for 25 years, described her experience as frustrating; she had to travel to City Hall to pay a bill that she normally settled with a few clicks online. Other residents reported similar difficulties with trash‑collection fees, parking‑ticket payments, and permit applications, prompting many to call city offices or visit in person. Local businesses that rely on timely permit issuance also faced delays, potentially affecting construction schedules and revenue streams. The reliance on phone calls and in‑person visits increased workload for city staff, who had to process transactions that would normally be automated.
Resident Reaction and Calls for Transparency
Herbster and others voiced disappointment with the city’s communication strategy, labeling it “poor” and asserting that the brief updates on social media were insufficient. She remarked that the lack of clear information made residents suspicious, wondering what other issues might be concealed. “I’m pretty pissed that it has not been broadcast,” Herbster said, questioning why the city had not disclosed the cyberattack sooner. This sentiment reflects a broader concern among citizens that timely, transparent disclosure is essential for maintaining trust, especially when essential services are disrupted.
Regional Context: Similar Attacks on Other Municipalities
University City’s experience is not isolated. In May 2024, Kansas City suffered a breach that knocked out its digital infrastructure, with officials initially offering little explanation for the prolonged outage. In early June 2025, a ransomware attack crippled network services in St. Joseph, Missouri, prompting officials to authorize more than $1 million to upgrade servers and firewalls. These incidents highlight a growing trend of cybercriminals targeting local government networks, which often contain valuable data and provide essential services but may lack the robust defenses of larger enterprises. The pattern underscores the need for municipalities to share threat intelligence and adopt standardized security practices.
Pre‑Existing IT Modernization Plans
Even before the attack, University City had planned to modernize its IT environment. The city had allocated $170,000 in its budget to migrate its accounting software to the cloud, a move intended to improve scalability, reduce reliance on on‑premises hardware, and simplify disaster recovery. To facilitate this transition, University City contracted Tyler Technologies, a provider of cloud‑based municipal software solutions, to host the services. The cyberattack has arguably accelerated the urgency of this migration, as cloud hosting can offer better resilience against localized network disruptions and enable faster restoration of critical functions.
Planned Network Infrastructure Upgrades
The city’s proposed fiscal 2027 budget also earmarks funds for updating aging network infrastructure across multiple facilities, including city hall, the police department, remote city offices, and the municipal parking garage. These upgrades aim to replace outdated hardware, improve bandwidth, and implement more robust segmentation and monitoring capabilities. By investing in a modern, resilient network foundation, University City hopes to reduce the likelihood of future outages and improve its ability to detect and respond to malicious activity swiftly.
Restoration Efforts and Timeline
According to Jones, restoration is being carried out in phases to ensure that each system is secured before being returned to service. This staggered approach allows the city to verify that vulnerabilities have been addressed and to prevent re‑infection as components come back online. Despite steady progress, officials have not yet announced a confirmed date for full restoration of all online services. The emphasis on security over speed reflects a cautious strategy designed to avoid repeating the disruption, though it also prolongs the inconvenience for residents who await the return of convenient digital options.
Conclusion and Lessons for Local Governments
The University City cyberattack serves as a cautionary tale for municipalities nationwide. It demonstrates how a successful intrusion can cripple everyday services, erode public trust, and expose gaps in communication and preparedness. The incident underscores several key lessons: the importance of timely and transparent disclosure to maintain citizen confidence; the value of proactive investments in cybersecurity, including network upgrades and cloud migration; and the necessity of clear incident‑response plans that involve external experts. By learning from this episode and the similar attacks in Kansas City and St. Joseph, other local governments can strengthen their defenses, improve their outreach, and better protect the essential services their communities rely on.

