Menu
Browse

Cyber Incident Victim: Clark County

Date:

Oct 2023

Location:

United States of America

Summary

Clark County experienced a cyberattack initially identified as suspicious network activity, prompting an investigation and emergency hiring of forensic consultants to assess impacts. Service disruptions temporarily affected public-facing systems including property information, geographic services, and jail roster webpages, though the latter was restored along with voter registration databases connected to a separate statewide system. Employee computers also experienced operational issues during the incident, but no evidence emerged of compromised resident or employee data. The county restored most services while continuing forensic analysis to determine the attack's scope.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On October 21, 2023, Clark County detected suspicious activity on its countywide network, prompting an immediate investigation. Initial public communications described the incident vaguely as "suspicious website activity," with county spokesperson Joni McAnally declining to confirm whether hackers were involved. The disruption forced the temporary shutdown of multiple online services, including the Property Information Center, Geographic Information Services (GIS) webpages, and the county jail roster. During an emergency board meeting that same day, Councilman Gary Medvigy characterized the event as a "cyberattack," emphasizing that such threats target organizations continuously. The council unanimously approved an emergency resolution to bypass standard procurement procedures and retain an unnamed forensic consultant to assess the attack's scope and impacts. County officials stated no evidence indicated compromise of employee or resident data during the initial phase of the investigation.

Cyber Incident Image

Information Technology teams worked to restore functionality, successfully bringing the main county website and jail roster page back online while other systems remained under evaluation. The Elections Office confirmed its voter registration database operated on Washington State's VoteWA system remained unaffected, resolving earlier delays in registration updates unrelated to the attack. By the time of the county's service update, GIS, Property Information Center, and jail systems were fully operational, though some employee computers required further remediation. Clark County reiterated its commitment to transparency regarding potential data exposure while continuing forensic analysis with external specialists. Network monitoring protocols enabled early detection of the anomaly, though investigators had not determined whether multiple incidents occurred or if the activity constituted a single coordinated attack at the time of reporting.

Sources
Sources available to members
2 sources