City of Atlanta
Incident posture
Linked entities
- Victim
- City of Atlanta
- Threat actors
- 1 actor
- Sources
- 2 sources
Timeline
Summary
A ransomware attack encrypted data and disrupted online services for the municipality, with outages affecting applications used to pay city bills and access court information. Officials detected the incident early in the morning when systems went down, and the city's new COO confirmed the attack impacted both public and internal applications while leaving public safety, water services, the airport, and payroll systems unaffected. The mayor warned residents who had shared personal information with the city to monitor their accounts for suspicious activity, as the full scope of the compromise remained under investigation. A screenshot reported by local media indicated the attackers demanded roughly $51,000 in ransom, and the malware involved was identified as resembling the Samas ransomware strain. Atlanta officials worked with the FBI, the Department of Homeland Security, Microsoft, and Cisco to investigate the incident, and the mayor stated that no decision had yet been made on paying the ransom.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In the early morning hours of Thursday, March 22, 2018, City of Atlanta officials became aware of a widespread outage affecting the municipality's information technology infrastructure when the disruption was first detected at 0540 local time. Atlanta's newly appointed Chief Operating Officer, Richard Cox, later confirmed that the city had "experienced a ransomware cyber attack" and that the malicious software had encrypted some of the city's data. The incident cut off access to a number of public-facing online services, including applications used by residents to pay city bills and systems used to access court information, while internal applications used by city staff were similarly impacted. Despite the breadth of the disruption, essential services continued to function; departments responsible for public safety, water services, and the operations of Hartsfield-Jackson Atlanta International Airport reported that they were operating without incident, and the city's payroll systems for employees were not affected.
At a press conference held that Thursday afternoon, Atlanta Mayor Keisha Lance Bottoms described the situation as "very serious" and stated that the full extent of the attack remained unknown and was under active investigation. She advised any individuals who had previously submitted personal information to the City of Atlanta through online channels that would have been stored on the compromised servers to remain vigilant regarding the potential misuse of their data and to monitor their online accounts for any suspicious activity. The mayor declined to state whether the city intended to pay the ransom demanded by the attackers, indicating that no decision on that matter had been reached. A screenshot of the ransom demand, reportedly provided by a city employee to Atlanta NBC affiliate WXIA, revealed that the attackers were seeking $51,000 to unlock the encrypted data.
The malware involved in the attack was reported by WXIA to resemble the "MSIL" or "Samas" strain, also known as SAMSAM, a ransomware variant that had been circulating since at least 2016. In response to the incident, Atlanta officials coordinated with multiple federal and private-sector partners to investigate the breach and restore affected systems. The city worked directly with the Federal Bureau of Investigation and the Department of Homeland Security, while also bringing in technical teams from Microsoft and Cisco to assist with the response effort. Throughout the day, city personnel continued to validate the scope of the compromise, working to determine which systems had been affected and which data, if any, had been rendered inaccessible by the encryption. The combination of encrypted city data, disrupted public-facing applications, and the potential exposure of personal information belonging to both employees and residents underscored the seriousness of the event, prompting the coordinated multi-agency investigation and a public advisory urging caution among those who had interacted with the city's online services.
Sources
Sources available to members: 2 sources.