CSIDB logo
Incident

Lee County

Incident posture

Attack window
Sep 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-02 00:00

Linked entities

Victim
Lee County
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity breach targeted Lee County's systems, prompting an immediate investigation and response from county technology experts. In reaction to the attack, officials temporarily disabled public access to the county's primary website to mitigate risks while working to resolve the incident. The disruption necessitated a public announcement by county leadership to address the ongoing situation.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 20, 2019, Lee County, Florida, publicly disclosed a cybersecurity attack affecting its systems during a news conference held by County Manager Roger Desjarlais. The breach prompted an immediate response from county technology personnel, who initiated an active investigation into the incident’s scope and origin. While specific technical details about the attack vector or perpetrator remained undisclosed, the county confirmed the compromise necessitated operational disruptions as a containment measure. Officials temporarily disabled public access to the primary county website, leegov.com, to prevent further unauthorized activity and protect system integrity. This action limited residents’ ability to access online services or information hosted through the domain. The county’s technology team prioritized isolating affected systems while maintaining critical operations where possible, though the full extent of compromised infrastructure was not detailed publicly.

The incident caused significant disruption to Lee County’s digital services, with the website outage representing the most immediate public impact. No specific information was released regarding data exfiltration, ransomware deployment, or financial motives behind the attack. Response efforts focused on forensic analysis to determine entry points and mitigate vulnerabilities, though findings were not disclosed during the initial announcement. County leadership emphasized transparency through the press conference but refrained from speculating about recovery timelines or long-term consequences. The proactive takedown of leegov.com underscored the county’s adherence to containment protocols despite the operational inconvenience. Restoration efforts proceeded under ongoing investigation, with no supplementary reports available in the provided source material to confirm final resolution details or additional repercussions.

Sources

Sources available to members: 1 source.

CSIDB