Cyber Incident Victim: Town of Didsbury
Date:
Mar 2021
Location:
Canada
Summary
The Town of Didsbury experienced a ransomware attack in which hackers encrypted municipal information systems and demanded payment to restore access. Officials publicly acknowledged the cyber incident several days after its occurrence, confirming the extortion attempt but refusing to disclose whether any ransom was paid to the perpetrators. The breach disrupted town operations, though specific consequences beyond system encryption were not detailed in initial reports. Municipal leadership maintained limited transparency regarding both the attack's operational impacts and their response strategy, focusing solely on confirming the ransomware's deployment and the criminals' financial demands without elaborating on mitigation efforts or data compromise.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 21, 2021, the Town of Didsbury, Alberta, experienced a cyber attack involving ransomware that encrypted municipal information systems. The incident was publicly disclosed by town officials on March 26, 2021, five days after the initial compromise. Attackers deployed malicious software that restricted access to critical town data and infrastructure, subsequently issuing a ransom demand in exchange for decrypting the locked systems. The operational disruption occurred on a Sunday, though specific details regarding detection timelines or initial intrusion vectors were not disclosed. Municipal representatives characterized the event as a targeted ransomware attack by unidentified threat actors, confirming the encryption of systems but not specifying which departments or services were directly impacted. No information was provided regarding the ransom amount demanded or whether data exfiltration occurred alongside the encryption.

Town officials, including Mayor Rhonda Hunter, acknowledged the ransom demand but declined to confirm whether payment had been made to the attackers. The municipality did not release technical specifics about the affected systems, restoration processes, or operational consequences stemming from the encryption. Public statements confirmed the incident's occurrence and the attackers' financial motivation but omitted details about system recovery timelines, potential data compromise, or costs associated with remediation. The disclosure followed standard crisis communication protocols by confirming the attack's basic parameters while withholding tactical response details that could compromise ongoing investigations or future security postures. No additional information was provided regarding law enforcement involvement, third-party cybersecurity assistance, or long-term impacts on municipal operations following the March 21 encryption event.
