CSIDB logo
Incident

Port Lavaca City Hall

Incident posture

Attack window
Feb 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-31 00:00

Linked entities

Victim
Port Lavaca City Hall
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Port Lavaca City Hall experienced a Ryuk ransomware attack that infiltrated its email system, disrupting servers, billing, and auto-pay operations while leaving water, sewer, and police systems unaffected. Attackers encrypted files and demanded a $200,000 ransom, which the city refused, opting instead to restore systems internally at a cost nearing $50,000; officials reported the incident to the FBI and reverted to manual payment collection while rebuilding databases with state and federal assistance.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Ryuk ransomware attack on Port Lavaca City Hall occurred in February 2020, disrupting municipal operations after infiltrating the city’s email system. The malware encrypted files on the local government’s primary server, disabling critical functions including billing and auto-pay systems. City Manager William DiLibero confirmed the attack forced a regression to manual payment collection methods, requiring staff to process cash, checks, and credit card transactions in person at City Hall. Mayor Jack Whitlow emphasized no data theft occurred, but ransomware operators demanded $200,000 to decrypt the locked files. Municipal services unrelated to the compromised server—including water utilities, sewer systems, and police department operations—remained functional throughout the incident.

City officials declined the ransom demand and engaged restoration efforts at an initial cost of $50,000, prioritizing local workforce involvement over capitulating to attackers. Whitlow stated recovery would require significant time to rebuild databases and fully reinstate digital payment infrastructure. The incident was reported to the FBI for investigation, with coordination extending to unspecified state and federal agencies. While partial system functionality was restored promptly, data recovery processes continued beyond the initial containment phase. The attack’s operational impact persisted through the reactivation period, particularly affecting revenue collection workflows reliant on automated processing. No secondary infections or collateral damage to industrial control systems were reported, contrasting with contemporaneous Ryuk attacks on maritime infrastructure that disrupted physical access controls and cargo monitoring networks.

Sources

Sources available to members: 1 source.

CSIDB