CSIDB logo
Incident

Lake County

Incident posture

Attack window
Aug 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-03 00:00

Linked entities

Victim
Lake County
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack targeted Lake County government systems, prompting an emergency shutdown of email services and multiple internal applications. The county's IT department responded by working through the weekend to purge affected systems, installing cybersecurity software across 3,000 employee laptops and remediating 40 compromised servers to restore operations.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On August 23, 2019, Lake County government systems experienced a ransomware attack that prompted an emergency shutdown of critical IT infrastructure. The attack disrupted email services and multiple internal applications used across county operations, forcing officials to publicly acknowledge the incident on August 24. County IT personnel immediately initiated containment measures by powering down affected systems to prevent further spread of the ransomware. The incident required extensive remediation efforts, with technicians working through the weekend to isolate and purge compromised components. No operational timelines for full restoration were provided in initial reports, though the disruption impacted routine government functions during the outage period.

The county's Information Technology Office, directed by Mark Pearman, focused on deploying cybersecurity software across approximately 3,000 employee laptops as a primary recovery measure. Concurrently, technicians addressed ransomware removal and system hardening on 40 county servers that sustained infections. These remediation activities were still underway as of August 22, indicating the attack preceded the public disclosure by at least one day. The response prioritized securing endpoint devices before reactivating network services, reflecting a phased containment strategy. No ransomware variant or specific attacker details were disclosed in available reports. The incident required sustained technical intervention across multiple days to restore core systems while maintaining emergency service capabilities throughout the recovery window.

Sources

Sources available to members: 1 source.

CSIDB