Key Takeaways
- Spartanburg County’s computer network has been offline for almost two weeks after the county isolated its systems to investigate suspicious activity.
- The South Carolina Law Enforcement Division (SLED) – specifically its SC Critical Infrastructure Cybersecurity (SC CIC) team – is leading the investigation.
- Essential services such as card payments, deed processing, court filings, and law‑enforcement reports are severely hampered, forcing staff to rely on handwritten notes and personal devices.
- County officials say the shutdown was a precautionary security step; they are gradually restoring access as verification continues.
- The outage follows a 2023 ransomware attack and a 2025 data breach, prompting employees and residents to demand stronger backup systems, compartmentalized networks, and proactive cyber‑risk planning.
- While offices remain open during normal hours, the lack of internet is causing frustration, delays, and concerns about the county’s ability to deliver core government services.
Current Situation and Scope of the Outage
Spartanburg County offices continue to operate during regular business hours, but nearly all internet‑dependent systems have been unavailable for approximately two weeks. The disruption began after county IT staff detected “questionable activity” on the network on Wednesday, June 10, 2026, prompting an immediate isolation protocol to safeguard data and infrastructure. As a result, services that rely on online connectivity—including computer workstations, internal phone systems, and public‑facing portals—have been taken offline. The county has posted a running list of affected departments on its website, urging residents to check the alert banner for the latest updates on what remains accessible and what workarounds are in place.
Official County Statement and SLED Investigation
On Monday, June 22, 2026, Spartanburg County issued a statement to WYFF News 4 explaining the rationale behind the network shutdown. The county emphasized that isolating the infrastructure was a “necessary security step” intended to give investigators and consultants time to confirm threats and strengthen defenses. The statement apologized for the inconvenience and thanked the public for its patience while remediation proceeds. Simultaneously, SLED’s South Carolina Critical Infrastructure Cybersecurity (SC CIC) team has assumed lead responsibility for probing the suspicious activity, examining logs, malware signatures, and potential entry points to determine whether the incident stems from a cyber‑attack, insider threat, or another source.
Impact on Essential Services and Daily Operations
The outage has crippled several core county functions. In the County Administration building, offices that handle licensing, property deeds, and card‑based payments cannot process transactions because the requisite databases and payment gateways are unreachable. Real‑estate professionals, such as Pam Harrison, described having to carry physical copies of documents and rely on memory or handwritten notes to complete work that would normally be executed online. The Sheriff’s Office has reverted to handwritten incident reports; while investigations continue, the inability to query external databases or run background checks has introduced noticeable delays. Similarly, the Clerk of Court’s office reported that staff are forced to use personal laptops, phones, and cloud storage to fulfill filings and docket entries, a practice that conflicts with county policy prohibiting personal use of government equipment for non‑official tasks.
Staff Adaptations and Work‑Arounds
Faced with a sudden loss of digital tools, county employees have improvised to keep services moving. Many are using personal devices to access email, cloud storage, and online forms, effectively bridging the gap until county systems are restored. Handwritten logs and paper‑based tracking have become commonplace in law‑enforcement and clerk’s offices, though officials acknowledge that this approach slows workflow and increases the risk of transcription errors. Some departments have set up temporary “drop‑box” stations where residents can submit paper forms that staff later enter manually once connectivity returns. These stop‑gap measures illustrate both the resilience of the workforce and the fragility of relying on a single, centralized network for all operational needs.
Historical Context: Prior Cyber Incidents
The current outage is not an isolated event. Spartanburg County suffered a ransomware attack in April 2023 that encrypted portions of its data and forced a costly recovery effort. Less than two years later, in August 2025, the county experienced a data breach that exposed sensitive personal information. Both incidents prompted after‑action reviews and promises to bolster cybersecurity posture, yet the recurrence of a major network disruption suggests that recommended safeguards—such as regular patching, multi‑factor authentication, network segmentation, and immutable backups—may not have been fully implemented or tested. Employees and residents alike are voicing frustration that lessons from the past appear to have been insufficiently acted upon.
Calls for Improved Contingency Planning and Prevention
In the wake of the outage, staff and community members are urging county leaders to adopt more robust contingency plans. Pam Harrison questioned whether adequate backup data exists off‑site and stressed the need for redundant systems that can take over when primary networks fail. Clerk of Court Amy Cox advocated for a compartmentalized architecture, arguing that isolating critical services would prevent a single point of failure from shutting down the entire operation. Both employees emphasized the importance of regular cyber‑hygiene drills, investment in continuous monitoring tools, and clear communication protocols to inform the public promptly during future incidents. The consensus is that proactive prevention—rather than reactive isolation—will better protect citizens’ access to essential government services.
Conclusion and Outlook
While Spartanburg County’s offices remain open and essential functions continue through improvisation, the prolonged internet outage underscores significant vulnerabilities in the county’s IT infrastructure. The ongoing SLED‑led investigation will hopefully identify the root cause and lead to strengthened defenses. In the interim, the county’s gradual restoration of services, coupled with transparent updates via its website and alert banner, will be crucial to maintaining public trust. Moving forward, investing in segmented networks, reliable off‑site backups, and comprehensive incident‑response planning will be vital to ensure that future cyber threats do not again leave the county “dead in the water” and unable to fulfill its mandate to serve the community.

