Cyber Incident Victim: Port Lavaca City Hall
Date:
Feb 2020
Location:
United States of America
Summary
Port Lavaca City Hall experienced a Ryuk ransomware attack that infiltrated its email system, disrupting servers, billing, and auto-pay operations while leaving water, sewer, and police systems unaffected. Attackers encrypted files and demanded a $200,000 ransom, which the city refused, opting instead to restore systems internally at a cost nearing $50,000; officials reported the incident to the FBI and reverted to manual payment collection while rebuilding databases with state and federal assistance.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The Ryuk ransomware attack on Port Lavaca City Hall occurred in February 2020, disrupting municipal operations after infiltrating the city’s email system. The malware encrypted files on the local government’s primary server, disabling critical functions including billing and auto-pay systems. City Manager William DiLibero confirmed the attack forced a regression to manual payment collection methods, requiring staff to process cash, checks, and credit card transactions in person at City Hall. Mayor Jack Whitlow emphasized no data theft occurred, but ransomware operators demanded $200,000 to decrypt the locked files. Municipal services unrelated to the compromised server—including water utilities, sewer systems, and police department operations—remained functional throughout the incident.

City officials declined the ransom demand and engaged restoration efforts at an initial cost of $50,000, prioritizing local workforce involvement over capitulating to attackers. Whitlow stated recovery would require significant time to rebuild databases and fully reinstate digital payment infrastructure. The incident was reported to the FBI for investigation, with coordination extending to unspecified state and federal agencies. While partial system functionality was restored promptly, data recovery processes continued beyond the initial containment phase. The attack’s operational impact persisted through the reactivation period, particularly affecting revenue collection workflows reliant on automated processing. No secondary infections or collateral damage to industrial control systems were reported, contrasting with contemporaneous Ryuk attacks on maritime infrastructure that disrupted physical access controls and cargo monitoring networks.
