CSIDB logo
Incident

Dallas Central Appraisal District

Incident posture

Attack window
Nov 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-19 00:00

Linked entities

Victim
Dallas Central Appraisal District
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Dallas Central Appraisal District experienced a ransomware attack that disrupted its online services, including website access, server functionality, and email communications, for over a week. The organization, responsible for property valuations supporting tax assessments across Dallas County, publicly acknowledged the incident and collaborated with law enforcement agencies to restore operations.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Dallas Central Appraisal District (DCAD), responsible for appraising Dallas County properties for tax purposes, experienced a disruptive ransomware attack in early November 2022. On or around November 8, 2022, hackers compromised DCAD's entire system, rendering its website, servers, and email systems inaccessible. The organization publicly confirmed the incident via social media shortly after detection, characterizing it as a ransomware attack. DCAD immediately initiated response protocols, collaborating with unspecified authorities to investigate the breach and restore operations. The attack forced a complete shutdown of critical infrastructure, halting online services and internal communications. No specific threat actor group or ransom demands were disclosed in initial reports.

The sustained system outage significantly impaired DCAD's core operations for at least seven days, with services remaining offline as of November 15, 2022. Property appraisal workflows, public record access, and tax-related functions were disrupted due to the unavailability of digital systems. Employees faced operational challenges without email access, while citizens could not obtain property records or conduct online transactions. DCAD maintained public updates through alternative channels but provided no timeline for full restoration. Recovery efforts focused on rebuilding compromised infrastructure with external support, though no data theft or permanent data loss was confirmed. The incident underscored vulnerabilities in local government digital infrastructure without revealing technical specifics of the attack vector or remediation costs.

Sources

Sources available to members: 1 source.

CSIDB