CSIDB logo
Incident

Wayne County

Incident posture

Attack window
Oct 2024
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2025-12-27 00:00

Linked entities

Victim
Wayne County
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack using ransomware targeted Wayne County government systems, disrupting multiple services and prompting an investigation involving the FBI and Michigan State Police. The attack prevented jail inmates from being bonded out, halted online tax payments—though in-person payments remained available—and forced the Register of Deeds Office to close early, blocking real estate transactions and property record access. Defense attorneys reported inability to schedule client visits, while the prosecutor’s and clerk’s office websites experienced prolonged outages, though court operations and the prosecutor’s physical office later resumed normal functions. The full scope of compromised systems remained under assessment.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On October 2, 2024, Wayne County government experienced a cyberattack disrupting multiple services, with the attacker deploying ransomware and making a financial demand. County spokesman Doda Lulgjuraj confirmed the incident targeted internal systems, prompting an immediate investigation coordinated with the FBI and Michigan State Police. The attack compromised servers at the Wayne County Sheriff’s Office, preventing jail inmates from being bonded out and disrupting defense attorneys’ ability to schedule client visits. The Wayne County Treasurer’s Office suspended online tax payment processing, though in-person payments remained available. The Register of Deeds Office closed at noon, halting real estate transactions and property record services. Websites for the Wayne County Prosecutor’s Office and Clerk’s Office remained nonfunctional throughout Wednesday, though the Prosecutor’s Office clarified on Thursday that operations had resumed normally. The Third Circuit Court reported no service interruptions.

County officials did not disclose the ransomware amount, intrusion methods, or specific affected IT infrastructure. Service disruptions revealed broad impacts across law enforcement, financial, and property systems, though the full scope remained under assessment. The Sheriff’s Office server compromise directly impeded judicial processes, while the Treasurer’s and Register of Deeds’ operational changes indicated isolated system failures. No data theft or public safety risks were mentioned. The county’s cybersecurity partners continued investigating the attack’s origin and containment measures as of October 3, with no restoration timeline provided for remaining affected services.

Sources

Sources available to members: 1 source.

CSIDB