CSIDB logo
Incident

Anson County

Incident posture

Attack window
Jul 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-03 00:00

Linked entities

Victim
Anson County
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hackers launched coordinated cyberattacks impacting multiple local government agencies, including Anson County, alongside the City of Concord and Lincoln County Sheriff’s Office. The incidents disrupted websites and internal computer servers, with some services restored within hours while others remained offline for extended periods. Officials confirmed that the attackers did not access or compromise public information during the breach, though operational disruptions affected digital infrastructure across the targeted entities.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around July 25, 2019, hackers launched cyberattacks against multiple local government entities in North Carolina, including Anson County, the City of Concord, and the Lincoln County Sheriff’s Office. The coordinated attacks began overnight, disrupting web pages and servers across these agencies. By 5:00 p.m. on July 26, 2019, partial service restoration had occurred, though some systems remained offline. Officials confirmed the attackers compromised county and municipal infrastructure but emphasized no public information was accessed or exfiltrated during the breach. The incident caused operational disruptions to digital services, though the specific duration of downtime varied between affected organizations.

The attacks primarily impacted web-facing systems and backend servers, forcing agencies to take affected infrastructure offline for investigation and remediation. Restoration efforts progressed throughout July 26, with some entities fully recovering services while others continued working to resolve lingering issues. Officials from the targeted jurisdictions publicly acknowledged the cyber intrusions but did not disclose technical details about the attack vectors or specific compromised systems. No ransomware demands or data theft claims were reported, and authorities maintained that citizen data remained secure despite the service interruptions. Response activities focused on system recovery and forensic analysis to determine the scope of unauthorized access.

Sources

Sources available to members: 1 source.

CSIDB