Cyber Incident Victim: Ballard Northwest Senior Center
Date:
Mar 2019
Location:
United States of America
Summary
The Ballard Northwest Senior Center experienced a ransomware attack that encrypted its servers, rendering all files inaccessible and disrupting operations. The incident occurred shortly before its largest annual fundraising event, compounding existing planning delays caused by severe weather. Despite the attackers' ransom demands, the organization refused payment, and its IT team successfully recovered most data after extensive efforts. The attack significantly hindered preparation for the critical fundraiser, which supports services for approximately 4,000 local seniors, necessitating urgent community donations and volunteer assistance to mitigate the impact.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On or around March 7, 2019, the Ballard Northwest Senior Center experienced a ransomware attack that encrypted all files on its server, rendering systems inaccessible. Staff discovered the incident upon powering on computers, finding no data available and folders locked. The attack occurred weeks before the center’s annual "Spring for Seniors" auction gala, its primary fundraiser scheduled for March 24. Executive Director Carlye Teel confirmed the organization received a ransom demand but adhered to a strict non-payment policy. Sound Generations, the parent nonprofit, did not disclose the ransom amount through its unavailable IT manager. The center serves approximately 4,000 seniors across Ballard, Magnolia, and Queen Anne, relying heavily on self-generated funding for operations.

The ransomware exacerbated existing planning delays caused by February snowstorms, forcing staff to prioritize data recovery over event preparations. Sound Generations’ IT team spent over a week reconstructing most lost data without paying the ransom. Operational impacts included disrupted access to critical systems, temporary inability to coordinate programs, and diverted resources during a high-stakes fundraising period. Board member Paul Sivesind characterized the attack as exploiting organizational vulnerability. The center publicly appealed for auction item donations, gift certificates, ticket purchases, and volunteers to mitigate financial risks. By March 14, recovery efforts allowed limited functionality restoration, though staff continued scrambling to finalize event logistics amid residual system constraints.
