Delaware County's Cyberattack and the Missing 911 Boundary
The public record describes disruption across county justice systems, but it does not show where Emergency Services sat relative to the affected network.

Delaware County, Pennsylvania shut down its network on June 26 after detecting what it later described as a sophisticated cybercriminal attack. The operational consequences quickly moved beyond office computers.
Sheriff's deputies verified warrants from hard copy. Protection-from-abuse orders were driven to neighboring counties so personnel with working system access could enter them for service. The sheriff's office reported that its systems were offline, including inbound and outbound calls. Courthouse filings stalled, cases were handled out of order, and the county remained disconnected from the Pennsylvania Justice Network, or JNET, at least through July 7.
On July 10, the county confirmed that attackers had gained limited access and accessed data maintained within the network. It has not publicly identified the initial access method, the time the attackers spent inside, the data involved, or whether the incident was ransomware.
One architectural question also remains unanswered: where did the affected environment end relative to the county's 911 center?
There is no public evidence that 911 call handling failed. The absence of reported degradation suggests that it probably did not. The gap is narrower and more useful than an allegation of a hidden outage. County statements and published coverage do not document whether Emergency Services was outside the affected environment, which shared services crossed the boundary, or which control kept the intrusion from reaching it.
For an emergency communications center, that boundary matters as much as the services running inside it.
JNET turned a network outage into a field problem
JNET is the Commonwealth of Pennsylvania's criminal justice information broker. Authorized users rely on it to reach systems including statewide warrant search, CLEAN and NCIC queries, court dockets, and the protection-from-abuse database. JNET publishes a data-resources sheet specifically for 911 communications centers. It is not merely a courthouse or administrative dependency.
When access disappears, the work continues through slower and less current paths. A warrant check moves to paper or telephone. A protection order must be entered somewhere else. Information that normally arrives before a unit reaches a door may arrive later, or not during the decision window at all.
That kind of degradation is easy to understate because the underlying emergency service can remain available. Calls are still answered. Radios still transmit. Units still respond. The loss appears in the quality and speed of the information surrounding the response, which is much harder to reconstruct after systems return.
The effect was visible elsewhere in county operations. Broad + Liberty reported, citing MediaPA Now, that a records-system outage at George W. Hill Correctional Facility left roughly 50 people awaiting release stuck in intake. The county's communications director disputed that account. The disagreement should remain visible, but it does not change the confirmed pattern: shared justice systems became operational dependencies during the shutdown.
The 2020 separation cannot serve as a current diagram
Delaware County faced a ransomware incident in 2020 after attackers entered through phishing. County IT detected network anomalies on November 21, roughly ten weeks after the initial compromise described in later reporting.
Reporting at the time included an important architectural detail. The Bureau of Elections and Department of Emergency Services were unaffected because they used separate networks. The county could answer where the intrusion stopped, and the answer was reported.
That 2020 statement is evidence about the 2020 environment. It cannot establish the same separation in 2026.
The county has since completed a $38 million replacement of its public-safety radio system. The P25 network replaced a 500 MHz T-Band system dating to 1992 and distributed roughly 3,700 radios. County Council held a ribbon cutting on March 13, 15 weeks before the intrusion. The system had reportedly been fully operational since January.
The modernization added more than replacement radios. Reporting describes automated voice dispatch for fire and EMS, along with capabilities that allowed at least one police department to build a real-time map of officer locations. Those are useful operational improvements, and they also represent new systems and integrations within the emergency communications environment.
The radio project does not establish any connection to the cyberattack. A radio modernization does not necessarily change the data-network boundary, but it does not guarantee that the boundary remained unchanged either. Six years of identity, virtualization, management, monitoring, and vendor changes also sit between the 2020 statement and the June 2026 incident.
The county had a second reason to improve the radio system: security. Its interim emergency services director told County Council that people had purchased radios online, reprogrammed them, and interfered with police operations. That addresses one form of unauthorized access. It does not answer how the rebuilt communications environment depends on county enterprise services.
A constrained intrusion still needs an identified control
The county says protections added after 2020 repeatedly blocked attempts to expand the intrusion. That is consistent with controls limiting the scope of compromise, but the public record does not identify the decisive control.
It may have been network segmentation, identity restrictions, endpoint detection, access design, or the decision to shut down county networks. More than one may have mattered. Without the architecture and incident evidence, assigning credit to any single control would be speculation.
The distinction matters because a system can occupy a separate network and still depend on shared identity, virtualization, backups, name resolution, storage, remote access, monitoring, or a common management plane. Network segmentation does not provide operational independence when a service required to use or recover the segmented system remains inside the affected environment.
Delaware County's Emergency Services Department serves 575,000 residents, 65 fire departments, and 42 police departments. I found no county statement or published report that placed the department inside or outside the affected environment in 2026. The reporting included detailed questions about access, attribution, data, and response, but did not establish the Emergency Services boundary.
That leaves county operators with a practical test they do not need Delaware County's final forensic report to run.
Test the boundary by removing enterprise IT
An emergency communications center should maintain a plain-language dependency map of every system a telecommunicator uses during a shift. The map should include CAD, mapping, call recording, radio consoles, state justice access, alerting platforms, telephony, logging, and authentication. For each system, it should answer three questions:
Where does the service run?
Which shared services are required to use, administer, and recover it?
What remains available if county enterprise IT goes to zero?
This is not the same deliverable as a vendor network diagram. The point is to expose operational dependencies that cross an otherwise clean architectural boundary.
In my experience, identity is usually the first hidden dependency. A CAD server can be carefully segmented while the directory required to log into it is not. Virtualization, backups, and the management plane are the next places I would look. A survivable application is of little use if nobody can authenticate, its host cannot be managed, or its recovery path depends on the environment that was just shut down.
The next tabletop should assume that IT is the incident. The test begins after the usual instruction to call IT has already failed. CISA and SAFECOM's guidance on reducing emergency communications center cyber incidents through segmentation provides a useful starting point. SAFECOM also publishes continuity guidance for cyber disruptions in evolving 911 environments.
County IT has a related responsibility: revalidate the boundary after any major public-safety technology project. The review should include identity, virtualization, backup, monitoring, management access, remote support, and recovery. A previous statement that Emergency Services uses a separate network is a historical fact, not a permanent control assessment.
County leaders also need the legal trigger map
Architecture is not the only map that should exist before an incident. County leaders need a short, reviewed description of the state's notification triggers, owners, deadlines, and likely costs.
Under Pennsylvania's Breach of Personal Information Notification Act, a county must notify affected residents within seven business days after determining that a covered breach occurred. It must notify the district attorney within three business days after that determination. If notice must go to more than 500 affected Pennsylvania residents, the Attorney General must be notified concurrently.
The same 500-person threshold also triggers notice to nationwide consumer reporting agencies. When the statutory conditions are met, affected individuals whose names were accessed with a Social Security number, bank account number, driver's license number, or state ID number must receive 12 months of credit monitoring at no cost.
The trigger language is important. The resident-notification requirement follows a determination that a covered breach occurred, not the initial detection of suspicious activity. The general rule also applies to covered personal information that was, or is reasonably believed to have been, both accessed and acquired.
Delaware County's July 10 statement confirmed access to data. It did not state that covered personal information had been accessed and acquired or that the county had made a statutory determination. That statement alone therefore does not establish that the resident-notification deadline had begun. The county's internal forensic findings remain unknown.
As of July 18, 6ABC reported, citing unnamed sources, that no ransom had been paid. The investigation was still active, and the county said it would meet any legal notification obligations supported by the results.
The unresolved technical question is simpler. A county should be able to show where its emergency communications environment sits relative to enterprise IT, identify every shared dependency that crosses the boundary, and demonstrate what survives when the county network is deliberately shut down.
Delaware County's deputies had to answer that question operationally, with paper warrants and trips to neighboring counties. Other counties can answer it before an incident by documenting the dependency path and testing it.





