CSIDB logo
Incident

Yerington Paiute Tribe

Incident posture

Attack window
Dec 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-10 00:00

Linked entities

Victim
Yerington Paiute Tribe
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Yerington Paiute Tribe experienced a ransomware attack that disrupted all tribal operations, including administration and clinic networks. The attack rendered systems inaccessible, with no estimated timeline for restoration as negotiations continue. Despite the widespread disruption, no sensitive information was exposed or remained unencrypted during the incident.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On December 10, 2019, the Yerington Paiute Tribe experienced a ransomware attack that disrupted all tribal operations. The malicious software encrypted the tribe's systems, locking administrators out of critical functions across tribal programs, administrative offices, and healthcare networks at their clinic. Tribal Chairwoman Laurie Thom confirmed the incident involved a ransomware virus but clarified no sensitive information was exposed or left unencrypted during the attack. The encryption of systems caused immediate operational paralysis, preventing staff from accessing essential digital resources required for daily tribal services. No specific ransomware variant was publicly identified in available reports.

Response efforts began immediately following the attack, with negotiations initiated between the tribe and the unidentified threat actors. Thom acknowledged the negotiations were ongoing but provided no estimated timeline for restoring system access or resuming normal operations. The incident exclusively impacted digital systems, with no evidence of physical infrastructure damage or exfiltration of tribal data. The tribe maintained public transparency about the cyberattack's operational consequences while emphasizing no personal or confidential data breaches occurred. Recovery priorities focused on resolving the ransomware encryption through negotiation or technical remediation to reinstate critical services for the community.

Sources

Sources available to members: 1 source.

CSIDB