Cyber Incident Victim: Yerington Paiute Tribe
Date:
Dec 2019
Location:
United States of America
Summary
The Yerington Paiute Tribe experienced a ransomware attack that disrupted all tribal operations, including administration and clinic networks. The attack rendered systems inaccessible, with no estimated timeline for restoration as negotiations continue. Despite the widespread disruption, no sensitive information was exposed or remained unencrypted during the incident.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On December 10, 2019, the Yerington Paiute Tribe experienced a ransomware attack that disrupted all tribal operations. The malicious software encrypted the tribe's systems, locking administrators out of critical functions across tribal programs, administrative offices, and healthcare networks at their clinic. Tribal Chairwoman Laurie Thom confirmed the incident involved a ransomware virus but clarified no sensitive information was exposed or left unencrypted during the attack. The encryption of systems caused immediate operational paralysis, preventing staff from accessing essential digital resources required for daily tribal services. No specific ransomware variant was publicly identified in available reports.

Response efforts began immediately following the attack, with negotiations initiated between the tribe and the unidentified threat actors. Thom acknowledged the negotiations were ongoing but provided no estimated timeline for restoring system access or resuming normal operations. The incident exclusively impacted digital systems, with no evidence of physical infrastructure damage or exfiltration of tribal data. The tribe maintained public transparency about the cyberattack's operational consequences while emphasizing no personal or confidential data breaches occurred. Recovery priorities focused on resolving the ransomware encryption through negotiation or technical remediation to reinstate critical services for the community.
