Security1 publisherNot yet confirmed elsewhere2 min readPublished
Andover confirms its August attacker got inside town systems
Andover officials confirmed an attacker reached some town systems in the Aug. 13 cyberattack but still cannot say whether any data was taken. The town has set no date for finishing the review that decides who gets notified.
The Watch · Security desk

What happened
- Geoffroy did not identify the accessed systems or say whether they belong to the town government or to Andover Public Schools.
- On the evening of Aug. 13 the town brought in two outside firms, the law firm Constangy, Brooks, Smith & Prophete and the cybersecurity firm Vector3, and Vector3 is helping monitor more than 3,000 devices.
- A ransomware group known as WallStreet posted Andover as a purported victim on a dark-web site on Aug. 30, and no culprit has been named.
- The town says it did not make or authorize any payments in connection with the incident.
- As of Sept. 22, 40 days after the attack, the state Attorney General's Office had received no notice.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Until the town says which network the attacker reached, families with children in Andover Public Schools cannot tell whether their records are in scope.
- contradiction The Oct. 5 records response reported no bills or costs beyond the policy, while contractor agreements estimate at least $39,605 in initial work, so the town's two accounts of spending appear to conflict.
- cost The no-added-cost assurance covers the contractors only, leaving the $10,000 retention, overtime, replacement equipment and security upgrades without a public figure for what the town itself pays.
"The Town has identified unauthorized access to certain systems and is continuing to determine the nature, scope, and sensitivity of any data that may have been accessed or acquired," Chief Communications Officer Phil Geoffroy said in written answers to Andover News [5]. He said some of the material reviewed so far appears routine or publicly available, but the full data set has not been characterized [6]. Investigators still have to check any accessed data for personally identifiable information [9].
That check decides whether the state breach law, Chapter 93H, applies. If it does, the town has to notify the people affected, as well as the Attorney General's Office and state regulators [17]. On Sept. 28, Town Counsel Doug Heim told the Select Board it was unclear whether state-protected information was involved [11].
Access is the only confirmed fact. Thecyberexpress.com described the confirmation as the town's clearest admission that the Aug. 13 attack reached its systems, though not proof that anything was copied, removed or published [7]. The same report says the WallStreet listing proves neither that the group was responsible nor that data was stolen [15]. Geoffroy would not name the agencies the town has notified. "The Town is coordinating with appropriate legal, forensic, and governmental partners as required and cannot comment on any law enforcement-related aspects of the event at this time," he said [16].
The response contract allowed for contact with the attacker. Vector3's agreement set aside up to $3,000 for possible communication with the attacker and for monitoring negotiation channels for up to 60 days. Whether that provision was used is unconfirmed [14]. The town's cyber policy carries $100,000 of cyber-extortion coverage [3].
On cost, Geoffroy said the insurer pays the contractors directly [1]. "Subject to the limits of our policy, Andover will bear no additional costs for these contractors and bills will be paid by our insurer," he said [2]. The policy covers up to $1 million across several categories of cyber expense [3].
Containment came first. Officials secured and restored the network, then reconnected equipment across municipal and school offices, printers included [10]. The municipal and school network was disrupted for four days. VPN access stayed down while it was rebuilt, and shared drives were not fully back until Aug. 21 [20], eight days after the attack [22]. Public safety, municipal buildings, phones and town-operated utilities kept operating [20]. "Based on what is currently known, the Town does not believe this incident reflects a lack of investment in information technology or incident preparedness," Geoffroy said [19].
What to watch
- A Chapter 93H notice from Andover to the Attorney General's Office would be the first sign the review found protected personal information.
- Data appearing on WallStreet's dark-web site would be the first public evidence that files left Andover's network.
- The town's next update, promised "if/when appropriate," and whether it says school systems were reached.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives60
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
An Oct. 5 public records appeal response said the Town had received no bills and incurred no costs beyond its insurance policy, seemingly conflicting with agreements estimating at least $39,605 in initial Vector3 and Constangy work. The insurer pays them directly, Geoffroy said.
- [2]
"Subject to the limits of our policy, Andover will bear no additional costs for these contractors and bills will be paid by our insurer," Geoffroy said.
ReportedSupportedSource: Phil Geoffroy2 sources— create a free account to open themView cited source - [3]
The policy covers up to $1 million for several categories of cyber expenses and $100,000 for cyber-extortion, with a $10,000 retention on most categories. The Town did not address overtime, replacement equipment, security upgrades or the retention.
- [4]
An attacker got into some of Andover's computer systems during a cyberattack on Aug. 13, town officials confirmed Thursday, though they cannot yet say whether any data was taken.
- [5]
"The Town has identified unauthorized access to certain systems and is continuing to determine the nature, scope, and sensitivity of any data that may have been accessed or acquired," Chief Communications Officer Phil Geoffroy said in written answers to Andover News.
ReportedSupportedSource: Phil Geoffroy, Andover Chief Communications Officer, written answers to Andover NewsView cited source - [6]
Some reviewed material appears routine or publicly available, Geoffroy said, but the full data set remains uncharacterized.
- [7]
The confirmation is the Town's clearest admission that the Aug. 13 cyberattack reached its systems, though not proof of copying, removal or publication.
- [8]
Geoffroy did not identify the systems, say whether they belonged to the municipality or Andover Public Schools, or give a completion date for the investigation.
- [9]
Investigators must check any accessed data for personally identifiable information, Geoffroy said.
- [10]
Officials first secured and restored the network, reconnecting equipment, even printers, across municipal and school offices. Another update will come "if/when appropriate."
- [11]
Town Counsel Doug Heim told the Select Board on Sept. 28 that it was unclear whether state-protected information was involved.
- [12]
The Town hired law firm Constangy, Brooks, Smith & Prophete and cybersecurity firm Vector3 on the evening of Aug. 13. Vector3 is tracing how the attacker entered, reconstructing the attacker's activity, assessing whether data was accessed or removed, and helping monitor more than 3,000 devices.
- [13]
On ransom demands or negotiations, Geoffroy said only that the Town "did not make or authorize any payments in connection with this incident."
- [14]
Vector3's agreement allowed up to $3,000 for possible communication with the attacker and monitoring of negotiation channels for up to 60 days, though its use is unconfirmed.
- [15]
No culprit has been named. On Aug. 30, a ransomware group called WallStreet listed Andover as a purported victim on a dark-web site, which proves neither responsibility nor data theft.
- [16]
Geoffroy would not name agencies notified: "The Town is coordinating with appropriate legal, forensic, and governmental partners as required and cannot comment on any law enforcement-related aspects of the event at this time."
- [17]
If Chapter 93H, the Massachusetts breach law, applies, the Town must notify the Attorney General's Office, state regulators and affected people.
- [18]
The Attorney General's Office had received no notice as of Sept. 22.
- [19]
"Based on what is currently known, the Town does not believe this incident reflects a lack of investment in information technology or incident preparedness," Geoffroy said.
- [20]
The cyberattack disrupted the municipal and school network for four days, with some restoration continuing afterward. Shared drives returned fully Aug. 21, and VPN access stayed down during its rebuild. Public safety, municipal buildings, phones and Town-operated utilities kept operating.
- [21]
As of Sept. 22, 40 days had passed since the Aug. 13 attack without the Attorney General's Office receiving notice.
- [22]
Shared drives were fully restored eight days after the Aug. 13 attack.
Sources
1 independent publisher whose own reporting we read for this story.
- thecyberexpress.comAndover Confirms Cyberattack Reached Its Systems, Investigation Continues
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- RansomwareFollow
- Municipal CybersecurityFollow
- Data Breach NotificationFollow
- Cyber InsuranceFollow