CSIDB logo
Incident

Midland Information Technology Consortium

Incident posture

Attack window
Oct 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-27 00:00

Linked entities

Victim
Midland Information Technology Consortium
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack disrupted internet, email, and phone services for the Midland Information Technology Consortium and its 85 nonprofit partners, though services were subsequently restored with assurances of network security. An international investigation involving local law enforcement remains ongoing, with potential felony fraud and computer hacking charges pending despite no specific ransom demand being identified. Restoration efforts continue alongside forensic analysis, while officials commended the consortium's response and highlighted broader trends in ransomware threats.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On October 20, 2022, the Midland Information Technology Consortium (MITCON) suffered a ransomware attack disrupting internet, email, and phone services for its 85 partner organizations, most of which are nonprofits. The attack caused immediate operational interruptions across MITCON’s network, though no specific ransom demand was disclosed publicly. Midland Business Alliance President and CEO Tony Stamas confirmed on November 4, 2022, that internet, email, and phone services had been restored to all partners and that the network was deemed secure again. Full restoration efforts remained ongoing as of the November 8 article publication date, with some aspects dependent on an active international forensics investigation. The Midland Police Department participated in the inquiry, which was characterized as lengthy due to its cross-border scope. No threat actor group or attack vector was identified in available reporting.

The incident triggered a coordinated response involving digital forensics specialists and law enforcement agencies across multiple jurisdictions. MITCON’s leadership publicly acknowledged the team’s handling of the crisis, with Stamas contextualizing the attack amid a 78% global increase in ransomware incidents during 2021. While service restoration mitigated immediate operational impacts, the forensic investigation continued to determine the attack’s origin, methods, and potential data compromises. Criminal charges, if pursued, would focus on felony fraud and computer hacking violations. No evidence suggested data exfiltration or secondary attacks following the initial compromise. The consortium maintained public communication regarding service recovery milestones but did not disclose technical specifics of the attack or remediation measures, citing the ongoing investigation.

Sources

Sources available to members: 1 source.

CSIDB