CSIDB logo
Incident

Virginia Attorney General

Incident posture

Attack window
Feb 2025
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-09-02 16:54

Linked entities

Victim
Virginia Attorney General
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack struck the Virginia Attorney General's office, forcing nearly all of the agency's computer systems offline and prompting an investigation by Virginia State Police and other law enforcement officials. Chief Deputy Attorney General Steven Popps notified staff via email that systems including Net Docs, Outlook, Teams, OAG Fileshare, VPN access, and internet connectivity via the OAG network were taken down as a result of the incident. To accommodate affected attorneys, the Supreme Court of Virginia and the Court of Appeals of Virginia offered access to a paper court filing "basket" that attorneys had elected to use previously.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 1, 2025, it was publicly reported that the Virginia Attorney General's office had been struck by a cyberattack earlier in the week that forced officials off the agency's computer systems. The office is the state's top prosecutorial agency and is led by Attorney General Jason Miyares. According to the Richmond Times-Dispatch, which first reported the incident, Chief Deputy Attorney General Steven Popps sent an email to staff on Wednesday informing them that nearly all of the office's computer systems were offline as a result of the attack. The email indicated that law enforcement authorities, including the Virginia State Police, were investigating the incident. Miyares' office did not immediately respond to a request for comment on the cyberattack when the news was first reported.

The scope of the incident was broad, affecting nearly every component of the office's digital infrastructure. Popps' email specified that the offline systems included Net Docs, Outlook, Teams, the OAG Fileshare, VPN access, and internet connectivity via the OAG network. This widespread outage effectively severed the office's primary means of communication, document storage, file sharing, and remote access. Because the Attorney General's office provides legal services to the commonwealth's agencies, boards, commissions, colleges, and universities, and works with law enforcement throughout the state, the disruption had the potential to affect operations well beyond the office itself. The agency's attorneys were unable to rely on their standard digital tools for handling legal matters during the period of disruption.

In response to the loss of electronic filing and access capabilities, the Supreme Court of Virginia and the Court of Appeals of Virginia offered alternative procedures to keep legal business moving. According to the Times-Dispatch, the courts provided access to a paper court filing "basket" that attorneys had previously chosen to use. This accommodation allowed attorneys within the Attorney General's office, and potentially others affected by the outage, to continue submitting filings through a physical mechanism rather than through the usual electronic systems. The shift to paper filings represented an immediate workaround while the office's digital systems remained offline and the investigation into the cyberattack continued.

As of the date the incident was reported, the specific nature of the attack, the identity of any threat actor, and the method of intrusion had not been publicly disclosed. The investigation being conducted by the Virginia State Police, along with other law enforcement officials, was ongoing. There was no immediate confirmation of whether any data had been accessed, exfiltrated, or compromised during the incident, or whether the attack involved ransomware, malware, or another form of intrusion. Officials had not publicly stated an expected timeline for restoring the affected systems.

Sources

Sources available to members: 1 source.

CSIDB