CSIDB logo
Incident

City of Troy

Incident posture

Attack window
Jan 2017
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-08 00:00

Linked entities

Victim
City of Troy
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack compromised the city's computer system, prompting officials to confirm the incident. IT staff isolated the virus, which appeared on Monday, and restored operations using backups. A new firewall is being installed to prevent future incidents. Separately, unrelated issues with online property tax bill payments arose and were resolved the same day.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 2, 2017, officials from the City of Troy confirmed that their computer system had been compromised by ransomware earlier that week. The attack was first detected on Monday, January 30, when malicious software infiltrated municipal systems, though specific entry vectors or attacker identities remained undisclosed. City information technology personnel responded by isolating the infected systems to prevent further spread across the network. Mayor Patrick Madden's spokesman, John Salka, publicly acknowledged the incident while emphasizing that critical backups allowed for system restoration without paying ransom demands. The disruption occurred alongside unrelated technical issues affecting online property tax payments on the same Monday, though officials clarified these events were coincidental rather than connected to the cyber intrusion. No operational downtime or data loss was reported due to the availability of functional backups.

The city's restoration process involved rebuilding affected systems from pre-existing backups, with full recovery achieved by Thursday's announcement. Concurrently, Troy's IT department initiated deployment of a new firewall infrastructure designed to strengthen defenses against future ransomware attacks. Salka confirmed both the resolution of the ransomware incident and the separate property tax payment system glitch, though technical specifics regarding impacted departments or operational consequences remained unstated. Municipal operations resumed normally following containment, with no evidence suggesting data exfiltration or secondary infections. The incident concluded with proactive security enhancements underway but no disclosed forensic findings about the attackers' methodology or demands.

Sources

Sources available to members: 1 source.

CSIDB