On 28 July 2025, three days after the attack began, the City of Saint Paul shut down its broader network in order to stop the attacker and eradicate them from city systems.
The Corpus Has Very Few Files Where This Happens
Victoria’s Secret took its e-commerce estate offline at 25-0526. A steel producer halted production on detection at 25-0505. Pakistan Petroleum isolated non-critical services at 25-0807.
Each was partial. A municipality shutting down its whole network is a decision to stop delivering most services in order to guarantee eviction — and it is a decision made under maximum uncertainty, three days in, without knowing the full extent.
Total Shutdown Is The Only Containment That Is Certain
This corpus repeatedly records the eviction problem: you cannot confirm you have removed an adversary whose signature is legitimate activity, at 25-0522, and a patched server can still be serving stolen keys, at 25-0723.
Disconnecting everything resolves that. It is expensive, visible, and the only action in this database that produces a certain answer to "are they still in?"
It Also Looks Identical To The Attack Having Caused It
This desk filed the complaint at 25-0526: deliberate containment outages are indistinguishable from outside from the attack having caused the outage, and organisations that act decisively look worse in the coverage than organisations that quietly stay up.
Saint Paul’s systems went dark on 28 July. From a resident’s position that was the attack. It was the response, and this file records it as such because almost nothing else in the corpus does.
Compiled from city statements and public reporting, listed below. Whether the shutdown fully evicted the actor is the city’s characterisation. Corrections: corrections@forensicpost.com.
- Cyber incident information hubCity of Saint Paul
- How St. Paul, Minn., recovered from a ransomware attackGovTech