Menu
Browse

Cyber Incident Victim: Bowie County

Date:

Dec 2020

Location:

United States of America

Summary

A ransomware attack disrupted government operations across multiple counties and cities, including Bowie County, causing significant outages affecting courthouse systems, BiState, and other agencies. The malicious activity was detected on the shared network serving these entities, with evidence indicating the ransomware had infiltrated systems prior to late November. While a data incident occurred, preliminary assessments found no confirmation of compromised personal information. Critical water services remained operational despite the attack. Recovery efforts involving system repairs are ongoing alongside an active investigation, though the full scope of the incident remains unclear.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On December 6, 2020, a ransomware attack disrupted computer systems across Bowie County and Miller County, Texas, causing widespread operational outages. The attack forced the shutdown of computers at the Bowie County Courthouse, BiState Justice Center, and other unspecified government agencies, as confirmed by Bowie County 202nd District Court Judge John Tidwell. The Texarkana Water Utility’s Information Technology Department detected suspicious network activity on the same day, triggering an investigation that revealed a ransomware compromise affecting the shared network infrastructure serving Bowie County and the cities of Texarkana, Texas, and Texarkana, Arkansas. Forensic analysis determined the ransomware had infiltrated the network prior to November 26, 2020, though the exact intrusion timeline remained unclear at the time of reporting. While authorities confirmed a data incident occurred, no evidence indicated personal information had been compromised during the attack. Critical water service operations were maintained without interruption despite the network compromise.

Cyber Incident Image

The coordinated response involved immediate containment measures, including isolating affected systems to prevent further spread of the ransomware. Repair efforts focused on restoring individual PCs and infrastructure components, though officials acknowledged the full scope of impacted systems and data remained undetermined as of the initial disclosure. An active investigation involving undisclosed partners was underway, with authorities withholding specific technical details to preserve investigative integrity. Public communications emphasized ongoing assessments of the attack’s duration, entry vectors, and total operational consequences while assuring continuity of essential municipal services. No ransomware group attribution, financial demands, or data exfiltration claims were disclosed in the initial statements from county or city officials.

Sources
Sources available to members
1 source