Georgia Superior Court Clerks’ Cooperative Authority
Incident posture
Linked entities
- Victim
- Georgia Superior Court Clerks’ Cooperative Authority
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
A ransomware group identified as Devman claimed responsibility for a cyberattack on the Georgia Superior Court Clerks’ Cooperative Authority. The group stated that the intrusion disrupted core administrative functions across the state’s judiciary. The incident was reported in a cybersecurity news feed that tracks ransomware claims against government entities. No further details about data loss, ransom demands, or restoration timelines were provided in the report.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On November 25, 2025, a ransomware group identified as Devman claimed responsibility for a cyberattack targeting the Georgia Superior Court Clerks’ Cooperative Authority (GSCCCA). The claim was made public via a ransomware gang statement. The attack targeted the GSCCCA, which provides administrative support to Georgia’s superior court clerks. The group asserted that it had successfully infiltrated the organization's systems. The incident was reported in a cybersecurity news abstract on that date. The abstract noted that the attack disrupted core administrative functions. The disruption affected operations across Georgia’s judiciary. The nature of the ransomware payload was not detailed in the source. The claim highlighted the group's focus on governmental entities. The attack added to a series of ransomware incidents reported in late 2025.
The disruption of core administrative functions impaired the ability of court clerks to perform essential duties. This impact hindered processing of court filings, record maintenance, and other judicial support services across the state. The extent of data exfiltration or encryption was not specified in the available source. No further details about detection timelines, containment measures, or recovery efforts were provided in the source material. The incident contributed to the observed trend of ransomware attacks targeting government agencies in 2025. The statement from Devman served as the primary public acknowledgment of the event. No additional statements from GSCCCA or law enforcement were included in the source. The narrative is limited to the information presented in the abstract. The incident remains documented as a ransomware claim against the Georgia Superior Court Clerks’ Cooperative Authority.
Sources
Sources available to members: 1 source.