CSIDB logo
Incident

Riviera Beach

Incident posture

Attack window
May 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-04 00:00

Linked entities

Victim
Riviera Beach
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Florida city paid a $600,000 ransom to hackers following a ransomware attack that encrypted municipal records, initiated by an employee clicking a malicious email link. The incident disrupted email services and emergency dispatch operations, prompting additional expenditures of nearly $1 million for new hardware, while federal agencies investigated the breach.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Riviera Beach ransomware attack began in late May 2019 when hackers infiltrated the Florida city's computer systems through a phishing email. An employee inadvertently clicked on a malicious link within the email, enabling attackers to upload malware that encrypted municipal records and paralyzed critical operations. The breach severely disrupted city services, with immediate impacts including the complete shutdown of the email system and compromised emergency response capabilities. 911 dispatchers lost the ability to enter calls into computer systems, creating operational challenges for public safety personnel. The encryption of city records left officials unable to access essential administrative and operational data, forcing many municipal functions into manual processes.

On June 19, 2019, the Riviera Beach City Council unanimously authorized a $600,000 ransom payment to the attackers in hopes of recovering their encrypted systems. This decision followed three weeks of sustained system outages and preceded a separate $1 million allocation for new computer hardware to replace compromised infrastructure. Multiple federal agencies including the FBI, Department of Homeland Security, and U.S. Secret Service initiated investigations into the attack. The incident exemplified broader ransomware trends affecting municipal governments, with similar attacks previously targeting cities including Atlanta, Newark, and Sarasota. Recovery efforts focused on system restoration through ransom negotiations and hardware replacement while investigators worked to trace the attack's origins and methodology.

Sources

Sources available to members: 1 source.

CSIDB