Menu
Browse

Cyber Incident Victim: Riviera Beach

Date:

May 2019

Location:

United States of America

Summary

A Florida city paid a $600,000 ransom to hackers following a ransomware attack that encrypted municipal records, initiated by an employee clicking a malicious email link. The incident disrupted email services and emergency dispatch operations, prompting additional expenditures of nearly $1 million for new hardware, while federal agencies investigated the breach.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The Riviera Beach ransomware attack began in late May 2019 when hackers infiltrated the Florida city's computer systems through a phishing email. An employee inadvertently clicked on a malicious link within the email, enabling attackers to upload malware that encrypted municipal records and paralyzed critical operations. The breach severely disrupted city services, with immediate impacts including the complete shutdown of the email system and compromised emergency response capabilities. 911 dispatchers lost the ability to enter calls into computer systems, creating operational challenges for public safety personnel. The encryption of city records left officials unable to access essential administrative and operational data, forcing many municipal functions into manual processes.

Cyber Incident Image

On June 19, 2019, the Riviera Beach City Council unanimously authorized a $600,000 ransom payment to the attackers in hopes of recovering their encrypted systems. This decision followed three weeks of sustained system outages and preceded a separate $1 million allocation for new computer hardware to replace compromised infrastructure. Multiple federal agencies including the FBI, Department of Homeland Security, and U.S. Secret Service initiated investigations into the attack. The incident exemplified broader ransomware trends affecting municipal governments, with similar attacks previously targeting cities including Atlanta, Newark, and Sarasota. Recovery efforts focused on system restoration through ransom negotiations and hardware replacement while investigators worked to trace the attack's origins and methodology.

Sources
Sources available to members
1 source