San Antonio Ransomware Attack Lessons From 5 Local Incidents

The City of San Antonio has no publicly confirmed ransomware attack on its own systems. The ones with a paper trail hit organizations around it. Judson ISD paid $547,000 in 2021, the appraisal district restored from backups in 2022, Uvalde CISD closed for a week in 2025, and UTSA pulled systems offline in August 2026. Each one left a lesson a San Antonio business can act on this month. For the protection side, see our cybersecurity services in San Antonio.

San Antonio ransomware attack lessons come from Judson ISD, the Bexar County Appraisal District, UTSA, Uvalde CISD and the Canvas outage, not City Hall. They teach 5 things. Test backups, plan for data theft, read your insurance, isolate building systems and map vendors.

I’m the CTO at Uprite. I read incident reports for a living, and I’ll be honest about why this post exists.

People keep searching for a City of San Antonio ransomware attack. A lot of people. So I went looking for the incident, through city press releases, local news archives and state announcements, and there isn’t one on the public record as of September 2026. What San Antonio does have is a cluster of well documented attacks on schools, a university and a county appraisal office, a few of which published unusually honest accounts of what went wrong. Those are more useful to a business owner than a city hall story would have been anyway. Far more useful.

Why? Because a 40-person company runs its IT a lot more like a school district’s business office than like a city of 1.5 million people.

IT technician unplugging network cables from a server rack during an early morning ransomware response

Was the City of San Antonio hit by ransomware?

No publicly confirmed ransomware attack has encrypted City of San Antonio systems as of September 2026. The incidents people usually mean hit other San Antonio area organizations, including Judson ISD in 2021, the Bexar County Appraisal District in 2022 and UTSA in 2026. City departments weren’t the victim in any of them. Good news, mostly.

That’s not luck, exactly. Back in 2021 the city’s chief security officer, Patsy Boozer, described joint cyber exercises with CPS Energy, SAWS and federal agents, plus the unglamorous basics of patching servers and watching alerts. Boring work. It works.

Other Texas cities weren’t so fortunate. In August 2019 a single coordinated campaign hit 23 Texas local governments at once. Mission, down in the Rio Grande Valley, is another Texas city that got hit, and Governor Abbott named it when he signed House Bill 150 in San Antonio on June 2, 2025, creating the $135 million Texas Cyber Command headquartered at UTSA. And Dallas had its own City Hall attack in 2023, which we broke down separately in what Dallas City Hall learned the hard way.

So if you landed here looking for a San Antonio city government breach, that’s the answer. The lessons below come from the attacks that did happen here.

Which San Antonio area ransomware incidents have a public record?

Five incidents that touched San Antonio organizations, or landed within about 80 miles of downtown, have enough published detail to learn from. I kept this list to primary accounts, official statements and local reporting that quotes named officials. No rumor, no dark web chatter.

IncidentWhenWhat went downHow it ended
Judson ISD (Live Oak)June 2021Every server and desktop, backups, email, phones, payroll, door access and camerasPaid $547,000 to stop a data leak, 428,761 people affected, recovery took over a year
Bexar County Appraisal DistrictMarch 2022Email and several internal systems, some damaged filesRestored from backups in roughly 1 to 2 days, property records database untouched
Uvalde CISDSeptember 2025Internet, phones, HVAC, security cameras and visitor managementCampuses closed for a week, no data breach found, phones came back last
Canvas (Instructure) outageMay 2026A cloud learning platform used by UTSA, UIW, Alamo Colleges and SAISDRansom notes posted during finals week, local schools rescheduled exams
UTSAAugust 2026Registration, payments and phones taken offline on purposeThreat contained at the network edge, fall classes delayed, no evidence of data theft

Only one of these involved a San Antonio public body actually paying a ransom, and it’s the one that later explained its decision in writing to Congress, in more detail than most companies ever share. It’s the most detailed public account of a ransomware attack I’ve read from any Texas organization, so it gets the most space here.

What did Judson ISD’s congressional testimony reveal?

In September 2023, Judson ISD’s Assistant Superintendent of Technology, Dr. Lacey Gosch, gave written testimony to a U.S. House oversight subcommittee on the district’s 2021 attack. It’s 8 pages. Read all of it if you run a business. It’s worth the time.

The short version goes like this. On June 17, 2021, a technician noticed a problem in the middle of the night, lost access to every internal system about 2 hours later, and by the time he reached the office every screen showed a ransom note from a group called PYSA, which the testimony describes as a strain that picked victims by their ability to pay. The attackers came in through a single technology employee’s device and pivoted through a video streaming server that was supposed to have no outside connection at all.

Then it got worse.

The district lost email, document access, payroll, purchasing, building access control and security cameras. It called local police, the county and the FBI. According to the testimony, each agency offered a case number and some reading material, and no law enforcement officer came to the property. Gosch had been in the job for 34 days.

Three details in that document matter more to a business owner than the headline ransom figure, and each one is its own lesson below.

Lesson 1. Why didn’t Judson’s backups save it?

Because the backups reported success while the ransomware was quietly encrypting and deleting them. The testimony says the virtual server backups kept generating “successful” notifications, and the systems engineer discovered the malware was destroying each copy right after it was made. Green checkmarks. Nothing behind them. Nobody caught it in time.

What saved the district was old fashioned. The team had pulled removable drive backups the day before the attack and stored them off site, and those drives were intact. That’s the whole reason critical financial and student data came back. Cheap drives did that.

Office worker disconnecting an external backup drive from a laptop to keep an offline copy of business data

I’d put this one first for any business in Bexar County. A backup job that reports success is telling you it ran. It isn’t telling you the copy survives an attacker who already has admin rights on the same network, and it certainly isn’t telling you anyone has restored from it lately. Ask your provider 3 questions this week. Is at least one copy immutable or physically offline? When was the last full restore test? Can the account that runs backups also delete them?

If the answer to the last one is yes, fix that first. Get the answers in writing. Our San Antonio disaster recovery page covers recovery targets, and these questions to ask an MSP about backup go further than I have room for here.

Lesson 2. Why pay a ransom when you can restore?

Judson could restore. It paid anyway. The district told Congress it paid about $547,000 “not to obtain our data but to ensure the deletion of data captured by the threat actors,” after the attackers produced a full file listing and handed over 5 specific files the district asked for as proof, including files from a 10 year span.

That’s double extortion, and it changes the whole math. Good backups solve encryption. That’s the trap. They do nothing about a copy of your payroll file sitting on someone else’s server.

And the decryption keys the district received? The testimony says they contained additional malware, and the team stopped using them. Think about that. Paying bought a promise about deleted data. It didn’t buy a clean recovery.

Data theft is now the normal pattern, not the exception. The Verizon 2026 Data Breach Investigations Report found ransomware in 48% of breaches, and the pressure point in most of those cases is the stolen data. For a San Antonio business the practical takeaway is to hold less sensitive data and encrypt what you keep at rest. Gosch’s own recommendation list says it bluntly, that ransomware “is not looking at data in motion.” If your HR folder is a shared drive of scanned driver’s licenses from 2014, that folder is your ransom note waiting to be written.

Whether to pay is its own decision with its own legal traps. We cover the payment question and the first 72 hours in ransomware recovery in Texas.

Lesson 3. What does cyber insurance actually pay for?

Less than owners assume. Judson carried what the testimony calls a sizable cyber policy, and it helped. The policy paid for attorneys, public relations, the threat actor hunt, data mining and notification letters, and it brought in the forensic firm BlueVoyant.

But it didn’t cover the ransom payment. It didn’t cover upgrades to prevent a repeat. Both hurt.

Cost Judson facedCovered by its policy?
Breach attorneysYes
Communications and PR supportYes
Forensic hunt for the attackersYes
Data mining to find who was affected, plus notificationYes
The $547,000 ransomNo
Security upgrades and repairs afterwardNo

That table describes one public school district’s policy as it stood in 2021, so treat it as an example of how coverage gets carved up rather than a prediction of what your own carrier will pay. Yours will differ, which is exactly the point. Pull the declarations page and read it before you need it. Today, ideally.

The part that surprised me more was the waiting. Because the district wanted to protect its insurance reimbursement, it was asked not to start recovery until the forensic review finished. It waited about 2 weeks, then started rebuilding on its own because school opened in under 30 days. The forensic work itself didn’t wrap up until June 13, 2022. If your policy requires a panel forensic firm, find out now whether you’re allowed to restore operations while they investigate, and who at your company has the authority to say go. Judson needed an emergency board vote in the first 24 hours to get that authority. Decide yours now.

We’ve written about answering the cyber insurance application honestly, and that matters here too. A policy you misrepresented on the application may not pay at all.

Lesson 4. What did the appraisal district and UTSA get right?

Both limited the blast radius. That’s the whole lesson, and it’s worth seeing twice.

When ransomware reached the Bexar County Appraisal District on a Sunday morning in March 2022, email and several systems went down and some files were damaged. But the appraisal records database was not accessed, the public website stayed up, the phones kept working, and the district restored from its own backups in an estimated 1 to 2 days. Assistant Chief Appraiser Scott Griscom said the attack appeared to arrive through email even though nobody seemed to have clicked a link. Staff notified the FBI immediately. Fast and boring.

UTSA is the newer story. Over a weekend in August 2026 the university detected unauthorized activity, took registration, payment and phone services offline on purpose, and pushed back the start of fall classes. Chief Technology Officer Michael Schnabel told reporters the threat was contained at the network edge before it reached core systems, with no evidence that university data was accessed or taken. Not confirmed as ransomware, for the record.

Two different organizations, one shared habit. Someone had decided in advance which systems could be sacrificed and which had to stay separate.

Pulling the plug on your own payments and phones during the busiest week of your year feels terrible, and every instinct in the building will argue for keeping things running a little longer. It’s still a far better week than Judson’s. A business owner should know, before anything happens, which systems they’d shut down first and whether their managed provider can do that at 2 in the morning without waiting for a callback. We keep a live San Antonio office on Radium Street and publish a 5-minute average first response for exactly that reason. Speed at hour 1 decides what hour 48 looks like.

Lesson 5. What happens when the systems nobody calls IT go down?

They go down with everything else. Uvalde CISD, about 80 miles west of San Antonio, closed every campus for a week in September 2025 after ransomware knocked out internet, phones, heating and air conditioning, security cameras and visitor management. Investigators found no data breach. Didn’t matter. The buildings still couldn’t open safely.

Judson lost building access control and cameras too. That’s a pattern.

Look around your own office. The door badge system, the camera recorder in the back closet, the phone system, the smart thermostat and the label printer on the warehouse floor are often sitting on the same flat network as the accounting PC. Nobody thinks of them as IT until they stop. Then everyone does. Uvalde’s phones were the last system restored, and if your business takes orders by phone that’s worth a long pause. Our San Antonio business phone service page explains how hosted VoIP keeps calls routing when the office network is down.

Segmenting those devices onto their own network is cheap compared with a week closed. Really cheap.

Lesson 6. Can a vendor’s breach take your business offline?

Yes, and May 2026 proved it locally. When the Canvas learning platform was attacked during finals week, UTSA, UIW, Alamo Colleges and SAISD all lost access to a system they didn’t run and couldn’t fix. ShinyHunters claimed the attack. Schools rescheduled exams. Students waited.

None of those schools did anything wrong inside their own networks, and there was nothing their IT teams could patch, restore or isolate that would have brought the platform back a minute sooner. Their vendor did.

Every San Antonio business has a Canvas equivalent. Your payroll provider, your practice management system, your ERP host, your email. Write down the 5 cloud services that would stop revenue within a day if they vanished, and next to each one write what you’d do instead. If the answer is “wait,” at least you’ll know that’s the plan. It’s a start.

The 6 lessons as a checklist for this month

Here’s the whole post as a working list. It’s sorted by what costs the least to fix. Start at the top.

LessonLocal incidentWhat to check this monthWho owns it
Backups can lieJudson ISDOne immutable or offline copy, and a restore test with a written resultIT provider, signed off by the owner
Stolen data is the leverJudson ISDDelete old sensitive files, encrypt what’s left at restOffice manager and IT
Insurance has gapsJudson ISDRead exclusions, panel vendor rules and who can authorize recoveryOwner and broker
Contain earlyBCAD, UTSAA written list of systems to isolate firstIT provider
Building systems countUvalde CISD, JudsonMove cameras, badges, phones and HVAC to their own networkIT provider
Vendors fail tooCanvas outageA fallback for the 5 cloud services revenue depends onOwner and department heads
Small business leadership team running a ransomware tabletop exercise around a conference table

What should a San Antonio business do in the first hour?

Judson’s team made the right early moves with no playbook, and Gosch wrote that the district’s formal continuity documents were “as useless as the paper that they were printed upon.” Plans that live in a binder fail. Plans people have rehearsed don’t. Rehearse yours.

Adapted from what Judson did and from the CISA #StopRansomware guide, here’s the order I’d follow. Print it.

  1. Disconnect affected machines from the network, but leave them powered on so evidence survives.
  2. Take Wi-Fi and remote access offline and change the passwords that control them.
  3. Call your managed IT or incident response provider, then your cyber insurer, before anyone starts wiping or rebuilding.
  4. Report it to the FBI through IC3 and keep the case number.
  5. Check whether your offline backups are intact and write down when each was last taken.
  6. Start a written timeline of who did what and when. Your lawyer and insurer will both ask.

Then there’s the Texas clock. If personal information of at least 250 Texans was involved, Business and Commerce Code section 521.053 requires notice to the Texas Attorney General within 30 days of determining the breach occurred, and affected people must be notified within 60. Judson’s breach touched 428,761 people, 221,000 of them outside Texas, so the notification job alone ran for months. Calendar it early.

Want the prevention side in more depth? Our step by step ransomware prevention plan covers the controls, and why San Antonio businesses are ransomware targets explains which local industries attackers pick first.

Where a managed security provider fits

I’ll be straightforward about my bias. We sell managed security, so of course I think it helps. Weigh that. But if you already have a staffed internal security team that tests restores quarterly and watches alerts overnight, you probably don’t need us for this. Most San Antonio companies with 20 to 200 employees don’t have that team, and that’s the gap Judson described, a small technology staff asked to watch more data than one person can. It’s common.

What a provider should bring is the dull stuff done on schedule. Endpoint detection on every device, not just servers. Restore tests with a report. Alerts watched at night. Segmented networks. A named person who picks up at 2 in the morning. That’s the job. If you’re comparing options, our managed security services in San Antonio page lists what’s included, and San Antonio cybersecurity pricing shows what it costs.

Not sure which of these 6 lessons your business would fail today? We’ll run a ransomware readiness assessment against your backups, insurance terms, network layout and vendor list, and hand you the fixes in order of cost.

Get an Assessment

Questions San Antonio owners ask about these attacks

Has the City of San Antonio ever been hit by ransomware?

Not according to any public record as of September 2026. There’s no city press release, state announcement or local news report of ransomware encrypting City of San Antonio systems. The well documented local incidents hit Judson ISD, the Bexar County Appraisal District, Uvalde CISD and UTSA.

How much did Judson ISD pay in the ransomware attack?

About $547,000 in Bitcoin, paid on June 29, 2021. The district says it paid to have stolen data deleted, not to decrypt its systems, because its offline drive backups could restore the critical data.

Do small businesses in San Antonio really get targeted?

Yes, and usually for the same reason Judson did. The testimony describes the PYSA group as picking victims by their ability to pay, not their size or fame. Small firms with thin security staff and valuable data fit that profile well. The FBI’s 2025 Internet Crime Report counted more than 1,400 ransomware complaints from businesses outside critical infrastructure, led by legal, contracting and engineering firms.

Will my cyber insurance pay the ransom?

Don’t assume it will. Judson’s policy covered lawyers, forensics, public relations and notification, but not the ransom or the upgrades afterward. Read your exclusions and your panel vendor rules with your broker now.

Is paying the ransom illegal in Texas?

Paying isn’t generally illegal for a private Texas business, though it’s risky. Payments to sanctioned groups can violate federal sanctions rules, which is why insurers and lawyers screen the attacker first. Paying also doesn’t guarantee much. Judson’s decryption keys arrived carrying more malware, and the district stopped using them. Talk to counsel before any payment conversation starts, and report the attack to the FBI either way.

What’s the single cheapest fix after reading all this?

Run a real restore test. Pick one important file share or database, restore it from backup to a separate location, and time it. It costs an afternoon, and it tells you whether you’d be in Judson’s position, with backups reporting success while the data behind them was already gone. If the test fails, you’ve found your first project.

About Author

Learn More