Menu
Browse

Cyber Incident Victim: Ballard Northwest Senior Center

Date:

Mar 2019

Location:

United States of America

Summary

The Ballard Northwest Senior Center experienced a ransomware attack that encrypted its servers, rendering all files inaccessible and disrupting operations. The incident occurred shortly before its largest annual fundraising event, compounding existing planning delays caused by severe weather. Despite the attackers' ransom demands, the organization refused payment, and its IT team successfully recovered most data after extensive efforts. The attack significantly hindered preparation for the critical fundraiser, which supports services for approximately 4,000 local seniors, necessitating urgent community donations and volunteer assistance to mitigate the impact.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On or around March 7, 2019, the Ballard Northwest Senior Center experienced a ransomware attack that encrypted all files on its server, rendering systems inaccessible. Staff discovered the incident upon powering on computers, finding no data available and folders locked. The attack occurred weeks before the center’s annual "Spring for Seniors" auction gala, its primary fundraiser scheduled for March 24. Executive Director Carlye Teel confirmed the organization received a ransom demand but adhered to a strict non-payment policy. Sound Generations, the parent nonprofit, did not disclose the ransom amount through its unavailable IT manager. The center serves approximately 4,000 seniors across Ballard, Magnolia, and Queen Anne, relying heavily on self-generated funding for operations.

Cyber Incident Image

The ransomware exacerbated existing planning delays caused by February snowstorms, forcing staff to prioritize data recovery over event preparations. Sound Generations’ IT team spent over a week reconstructing most lost data without paying the ransom. Operational impacts included disrupted access to critical systems, temporary inability to coordinate programs, and diverted resources during a high-stakes fundraising period. Board member Paul Sivesind characterized the attack as exploiting organizational vulnerability. The center publicly appealed for auction item donations, gift certificates, ticket purchases, and volunteers to mitigate financial risks. By March 14, recovery efforts allowed limited functionality restoration, though staff continued scrambling to finalize event logistics amid residual system constraints.

Sources
Sources available to members
1 source