Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

Andover confirms its August attacker got inside town systems

Andover officials confirmed an attacker reached some town systems in the Aug. 13 cyberattack but still cannot say whether any data was taken. The town has set no date for finishing the review that decides who gets notified.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Andover confirms its August attacker got inside town systems
Generated illustration

What happened

  • Geoffroy did not identify the accessed systems or say whether they belong to the town government or to Andover Public Schools.
  • On the evening of Aug. 13 the town brought in two outside firms, the law firm Constangy, Brooks, Smith & Prophete and the cybersecurity firm Vector3, and Vector3 is helping monitor more than 3,000 devices.
  • A ransomware group known as WallStreet posted Andover as a purported victim on a dark-web site on Aug. 30, and no culprit has been named.
  • The town says it did not make or authorize any payments in connection with the incident.
  • As of Sept. 22, 40 days after the attack, the state Attorney General's Office had received no notice.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Until the town says which network the attacker reached, families with children in Andover Public Schools cannot tell whether their records are in scope.
  • contradiction The Oct. 5 records response reported no bills or costs beyond the policy, while contractor agreements estimate at least $39,605 in initial work, so the town's two accounts of spending appear to conflict.
  • cost The no-added-cost assurance covers the contractors only, leaving the $10,000 retention, overtime, replacement equipment and security upgrades without a public figure for what the town itself pays.

"The Town has identified unauthorized access to certain systems and is continuing to determine the nature, scope, and sensitivity of any data that may have been accessed or acquired," Chief Communications Officer Phil Geoffroy said in written answers to Andover News [5]. He said some of the material reviewed so far appears routine or publicly available, but the full data set has not been characterized [6]. Investigators still have to check any accessed data for personally identifiable information [9].

That check decides whether the state breach law, Chapter 93H, applies. If it does, the town has to notify the people affected, as well as the Attorney General's Office and state regulators [17]. On Sept. 28, Town Counsel Doug Heim told the Select Board it was unclear whether state-protected information was involved [11].

Access is the only confirmed fact. Thecyberexpress.com described the confirmation as the town's clearest admission that the Aug. 13 attack reached its systems, though not proof that anything was copied, removed or published [7]. The same report says the WallStreet listing proves neither that the group was responsible nor that data was stolen [15]. Geoffroy would not name the agencies the town has notified. "The Town is coordinating with appropriate legal, forensic, and governmental partners as required and cannot comment on any law enforcement-related aspects of the event at this time," he said [16].

The response contract allowed for contact with the attacker. Vector3's agreement set aside up to $3,000 for possible communication with the attacker and for monitoring negotiation channels for up to 60 days. Whether that provision was used is unconfirmed [14]. The town's cyber policy carries $100,000 of cyber-extortion coverage [3].

On cost, Geoffroy said the insurer pays the contractors directly [1]. "Subject to the limits of our policy, Andover will bear no additional costs for these contractors and bills will be paid by our insurer," he said [2]. The policy covers up to $1 million across several categories of cyber expense [3].

Containment came first. Officials secured and restored the network, then reconnected equipment across municipal and school offices, printers included [10]. The municipal and school network was disrupted for four days. VPN access stayed down while it was rebuilt, and shared drives were not fully back until Aug. 21 [20], eight days after the attack [22]. Public safety, municipal buildings, phones and town-operated utilities kept operating [20]. "Based on what is currently known, the Town does not believe this incident reflects a lack of investment in information technology or incident preparedness," Geoffroy said [19].

What to watch

  • A Chapter 93H notice from Andover to the Attorney General's Office would be the first sign the review found protected personal information.
  • Data appearing on WallStreet's dark-web site would be the first public evidence that files left Andover's network.
  • The town's next update, promised "if/when appropriate," and whether it says school systems were reached.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence60
Adoption
Insufficient
Hype gap+5
Incentives60
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    An Oct. 5 public records appeal response said the Town had received no bills and incurred no costs beyond its insurance policy, seemingly conflicting with agreements estimating at least $39,605 in initial Vector3 and Constangy work. The insurer pays them directly, Geoffroy said.

  2. [2]

    "Subject to the limits of our policy, Andover will bear no additional costs for these contractors and bills will be paid by our insurer," Geoffroy said.

  3. [3]

    The policy covers up to $1 million for several categories of cyber expenses and $100,000 for cyber-extortion, with a $10,000 retention on most categories. The Town did not address overtime, replacement equipment, security upgrades or the retention.

Sources

1 independent publisher whose own reporting we read for this story.

  1. thecyberexpress.com

    1 article · October 8, 2026

    Andover Confirms Cyberattack Reached Its Systems, Investigation Continues

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories