County says sharing information about ‘suspicious activity’ in sheriff’s computer system would ‘jeopardize public safety’

photo by: Douglas County Sheriff's Office

A Douglas County Sheriff's Office vehicle is pictured in January 2022.

After the computer system in the Douglas County Sheriff’s Office underwent an apparently serious cyberattack, the office is declining to release any details about the matter, including whether the attack exposed people’s personal information or how much taxpayer money is being spent on addressing the problem.

The county’s public information officer, in denying a records request, has told the Journal-World that no information can be released about the incident because “such documents are protected from disclosure” under statutory exceptions to the Kansas Open Records Act — namely, that disclosure would implicate records “that are privileged under the rules of evidence” and that disclosure about a cybersecurity matter “would jeopardize public safety.”

The incident came to light recently, as the Journal-World reported, when the sheriff’s office indicated on its website that all services related to jail inmate reports and other matters would be “offline until further notice.”

The sheriff’s office was initially circumspect on the matter, only citing “technical issues,” but eventually acknowledged that it was investigating “suspicious activity” related to the office’s computer system. The office noted that 911 services were not affected.

Douglas County Sheriff Jay Armbrister, a Democrat, is an elected official whose office is in charge of various functions, such as law enforcement in the county, jail operations, inmate transport, providing courtroom security, serving legal papers such as summonses and subpoenas and executing court orders.

In response to about a dozen questions posed by the Journal-World, including whether the incident was caused by ransomware, whether anyone’s personal information had been exposed and whether a contract involving public money had been executed to address the matter, the office declined to answer.

“Given the ongoing investigation, we cannot answer many of these questions at this time,” sheriff’s office spokesman George Diepenbrock told the Journal-World in an email this week.

Diepenbrock provided only this statement: “The Sheriff’s Office takes the security of our network and data very seriously, and as soon as we became aware of the suspicious activity, we launched the investigation to determine the nature and scope of the activity.

As we continue to work through this process, certain services and systems have experienced intermittent outages. Certain services may be delayed as we continue to investigate, and we apologize for any inconvenience.

We want to reiterate regarding public safety that all services are fully functioning. Anyone experiencing an emergency should call 911 because there is no disruption in 911 services or the Sheriff’s Office response. All other county systems remain functional.”

The office would not confirm or deny that the incident was caused by ransomware or even whether email was affected.

In October of 2023, a Russian-based ransomware group infiltrated the computer system for Kansas’ courts, wreaking havoc on the system’s functionality and causing a major slowdown in court operations statewide.

The true nature of that attack, initially described only as a “security incident,” wasn’t revealed immediately. Eventually Kansas’ Supreme Court, saying that a review of the incident took time, acknowledged that it resulted from a “sophisticated foreign cyberattack” and that perpetrators “stole data and threatened to post it to a dark website.”

In May of 2024, seven months after the attack, the judicial branch revealed that about 150,000 people who had interacted with the courts might have had their data breached in the cyberattack, including Social Security numbers, driver’s licenses, government identification cards, payment card information, tax identification card numbers, passports, and health insurance policy information among other data.

People affected by the data breach were offered credit monitoring and identity protection services at no cost.

Kansas’ chief justice at the time also said that the judicial branch had implemented numerous new security controls and began using supplemental anti-malware tools. The Office of Judicial Administration also provided a timeline of the incident on the OJA’s website.