Cyber Incident Victim: Chilton County
Date:
Jul 2020
Location:
United States of America
Summary
A suspected ransomware attack disrupted an Alabama county's computer network, prompting a temporary system-wide shutdown to contain potential malware spread. The incident caused significant operational disruptions, particularly affecting the tag office and probate court records, rendering critical local records inaccessible for regular services. County officials advised residents to verify service availability before visiting affected departments. Response efforts included engaging a professional IT firm to assess system integrity and initiating an investigation to determine the attack's severity. Federal and state authorities, including the FBI's cyber division and the Alabama Attorney General’s Office, were notified of the breach.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On the morning of July 7, 2020, Chilton County, Alabama, experienced a suspected ransomware attack that prompted an immediate shutdown of its computer network. County Commission Chairman Joseph Parnell publicly announced the incident via Facebook, confirming the cyberattack had caused temporary disruptions to critical county services. The attack specifically impacted the tag office and probate court records systems, rendering local records required for regular courthouse operations inaccessible. This forced residents seeking county services to contact individual department clerks beforehand to verify record availability, significantly hampering routine administrative functions. The county implemented a proactive network closure across multiple departments to contain potential malware spread, though the exact method of initial compromise remained unspecified in public statements.

In response to the incident, Chilton County activated its existing cyber-policy by engaging a New York-based professional IT firm to assess system damage and recovery options. Parnell confirmed in a phone interview with the Clanton Advertiser that an active investigation was underway to determine the attack's severity and scope. Concurrently, the county notified federal and state authorities, including the FBI's cyber division and the Alabama Attorney General’s Office, about the breach. No ransom demands or threat actor details were disclosed publicly during the initial response phase. The coordinated containment strategy focused on isolating infected systems while maintaining essential services through alternative procedures during the network outage.
