Cyber Incident Victim: Dallas Central Appraisal District
Date:
Nov 2022
Location:
United States of America
Summary
The Dallas Central Appraisal District experienced a ransomware attack that disrupted its online services, including website access, server functionality, and email communications, for over a week. The organization, responsible for property valuations supporting tax assessments across Dallas County, publicly acknowledged the incident and collaborated with law enforcement agencies to restore operations.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The Dallas Central Appraisal District (DCAD), responsible for appraising Dallas County properties for tax purposes, experienced a disruptive ransomware attack in early November 2022. On or around November 8, 2022, hackers compromised DCAD's entire system, rendering its website, servers, and email systems inaccessible. The organization publicly confirmed the incident via social media shortly after detection, characterizing it as a ransomware attack. DCAD immediately initiated response protocols, collaborating with unspecified authorities to investigate the breach and restore operations. The attack forced a complete shutdown of critical infrastructure, halting online services and internal communications. No specific threat actor group or ransom demands were disclosed in initial reports.

The sustained system outage significantly impaired DCAD's core operations for at least seven days, with services remaining offline as of November 15, 2022. Property appraisal workflows, public record access, and tax-related functions were disrupted due to the unavailability of digital systems. Employees faced operational challenges without email access, while citizens could not obtain property records or conduct online transactions. DCAD maintained public updates through alternative channels but provided no timeline for full restoration. Recovery efforts focused on rebuilding compromised infrastructure with external support, though no data theft or permanent data loss was confirmed. The incident underscored vulnerabilities in local government digital infrastructure without revealing technical specifics of the attack vector or remediation costs.
