CSIDB logo
Incident

City of Kingman

Incident posture

Attack window
Feb 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-26 00:00

Linked entities

Victim
City of Kingman
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted the government computer systems of the City of Kingman, impacting operations across its entire network. The incident prompted collaboration with local and federal authorities, including the FBI, Department of Homeland Security, and Arizona National Guard Cyber Joint Task Force, to address the breach and mitigate its effects.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The City of Kingman, Arizona, experienced a significant cyberattack targeting its government computer systems, discovered on February 26, 2021. City spokeswoman Colleen Haines confirmed the incident in a public statement released on February 28, noting the attack impacted operations "throughout the entire computer system." Authorities detected the compromise on Friday, though the exact intrusion timeline and initial attack vector remained unspecified in public disclosures. The city activated its incident response protocols immediately upon discovery, initiating coordination with multiple law enforcement and cybersecurity agencies to contain the breach and assess damage.

Federal and state resources were mobilized to assist Kingman's recovery efforts, including the FBI, Department of Homeland Security (DHS), and the Arizona National Guard Cyber Joint Task Force. No operational details regarding containment measures—such as system isolation or forensic methodologies—were disclosed publicly. The attack disrupted municipal computer systems broadly, though the city did not specify which services or departments were most affected or whether data exfiltration occurred. No ransomware claims or explicit threat actor attribution appeared in initial reports. Recovery timelines and operational impacts on city services remained unclear as investigations continued with federal support. The collaborative response underscored the severity of the incident, though technical specifics about the attack's mechanism and full consequences were not released to the public during the immediate aftermath.

Sources

Sources available to members: 1 source.

CSIDB