CSIDB logo
Incident

Alexander City Government

Incident posture

Attack window
Jan 2023
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-09 17:55

Linked entities

Victim
Alexander City Government
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Alexander City experienced a ransomware attack that disrupted municipal operations, prompting an emergency council meeting after discovering the breach and receiving a ransom demand. The city engaged its cybersecurity insurance provider, which deployed a taskforce and contracted Codeware for incident response and legal support following council authorization. Attackers compromised both physical and virtual servers, altering administrative credentials and potentially tampering with backups, with evidence suggesting unauthorized network access lasting up to 10 days prior to detection. While phone systems were impaired, emergency services and utility billing remained functional during the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 24, 2023, Alexander City officials discovered a ransomware attack during morning operations at approximately 7 a.m., prompting an emergency city council meeting that same day. Mayor Woody Baird confirmed the attack involved a ransom demand delivered to the city, though the specific amount and payment terms were not disclosed. The city immediately engaged its cybersecurity insurance provider, which deployed a taskforce to manage the incident and recommended contracting Codeware, a software firm, for specialized IT legal advice and incident response support. During the council meeting, officials authorized an immediate deposit and signed an agreement to activate Codeware’s services, emphasizing urgency to initiate forensic tracking of the attackers. Initial assessments indicated the attack disrupted municipal phone systems, though critical services including 9-1-1 emergency response and utility payment processing remained operational.

City IT Director Joe Milam reported extensive infrastructure compromise, with both physical and virtual servers—including the vCenter virtualization management platform—rendered inaccessible due to altered administrative credentials. Milam recovered backup systems but expressed uncertainty regarding their integrity, noting attackers could have tampered with files during a potential seven-to-ten-day潜伏期 (潜伏期) prior to detection. The breach’s origin and full scope remained undetermined at the time of the council meeting, with no confirmation of data exfiltration or specific attacker identity. Council members unanimously approved Codeware’s engagement to pursue system recovery and investigate the intrusion. Operational impacts persisted through the disclosure period, primarily affecting internal communications and administrative functions, while response efforts focused on restoring systems from backups pending forensic validation.

Sources

Sources available to members: 1 source.

CSIDB