Menu
Browse

Cyber Incident Victim: Presque Isle Police Department

Date:

Apr 2021

Location:

United States of America

Summary

The Presque Isle Police Department experienced a ransomware attack where threat actors leaked partial data after a ransom deadline expired. Following the initial countdown expiration, attackers posted a "Coming Soon" message on their dark web site and later uploaded a non-functional 150 MB archive containing department files. The attackers subsequently reset the countdown timer, extending the extortion window by seven days for potential further data leaks or escalation. This incident demonstrates partial data exposure coupled with ongoing pressure tactics through deadline extensions by the unidentified threat group.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

The Presque Isle Police Department experienced a ransomware attack that culminated in a public extortion attempt by unidentified threat actors in April 2021. On April 18, 2021, a ransom deadline countdown displayed on the attackers’ dark web site expired at approximately 9:30 p.m., marked by a timer with red numerals counting down minutes and seconds to zero. Following the deadline’s expiration, the threat actors did not immediately execute their threatened data leak but instead placed their site “on hold” with a “Coming Soon” message indicating pending updates. This suggested a temporary pause in their actions despite the elapsed deadline. The Bangor Daily News initially reported on the incident prior to the countdown’s expiration, drawing public attention to the situation.

Cyber Incident Image

Subsequent to the Bangor Daily News’ coverage, the threat actors attempted to escalate pressure by uploading a 150 MB archive purportedly containing department data to their dark web site. However, the provided download link for this archive was non-functional, preventing immediate access to the allegedly leaked information. Following this incomplete data release attempt, the attackers reset their countdown timer, granting the Presque Isle Police Department an additional seven days to respond to their demands before threatening further data disclosures. This extension indicated a tactical shift in the attackers’ approach, prolonging the extortion timeline while maintaining uncertainty about the full scope and validity of the compromised data. The department’s operational status, specific data types involved, and any direct interactions between the department and the threat actors were not disclosed in available reports.

Sources
Sources available to members
1 source