Menu
Browse

Cyber Incident Victim: City of Wichita

Date:

May 2024

Location:

United States of America

Summary

The City of Wichita experienced a cybersecurity incident involving malware that encrypted certain municipal systems, leading to a proactive shutdown of its computer network to prevent further spread and causing temporary disruptions to online services. Technical difficulties impacted airport WiFi and flight information displays, while the municipality activated business continuity measures and engaged third-party specialists to securely restore operations. Officials are assessing potential data impacts but have not disclosed the responsible group due to operational security concerns, urging residents to monitor official updates during the ongoing review process.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On May 5, 2024, the City of Wichita, Kansas, publicly disclosed a cybersecurity incident involving malware that encrypted certain municipal computer systems. The attack occurred on Sunday, prompting immediate containment measures including the shutdown of the city’s entire computer network to prevent further propagation of the malware. This action resulted in temporary unavailability of unspecified online city services, though officials activated business continuity protocols where feasible to minimize operational disruptions. The City’s press release emphasized the deliberate nature of the network disconnection, stating it was necessary to securely vet systems before restoration. Concurrently, Wichita Dwight D. Eisenhower National Airport reported technical difficulties affecting its WiFi and real-time flight arrival/departure displays at 3 p.m. local time, though no direct attribution to the broader city incident was confirmed.

Cyber Incident Image

The City engaged third-party cybersecurity specialists to assist in forensic analysis and network restoration efforts, while declining to identify the threat actor group claiming responsibility for operational security reasons. Officials initiated a comprehensive review to assess potential data compromise, acknowledging the time-intensive nature of such investigations in their public communications. Residents were directed to a dedicated city webpage for incident updates and FAQs, with authorities emphasizing patience and restraint during the ongoing assessment. No further technical specifics regarding affected systems, data exposure risks, or malware variants were disclosed as of the initial announcement. Service disruptions remained unresolved at the time of reporting, with recovery timelines contingent upon completion of security validations.

Sources
Sources available to members
1 source