CSIDB logo
Incident

Jackson County

Incident posture

Attack window
Apr 2024
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-01 03:12

Linked entities

Victim
Jackson County
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Apr 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Jackson County experienced significant IT disruptions potentially linked to a ransomware attack, causing operational inconsistencies that rendered systems for tax payments, online property searches, marriage license processing, and inmate searches inoperative, leading to closures of Assessment, Collection, and Recorder of Deeds offices. Election systems remained unaffected during the incident. The county engaged law enforcement and cybersecurity contractors to investigate and secure systems, emphasizing no current evidence of data compromise while diagnostic efforts to confirm the attack's nature and restore services continued.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 2, 2024, Jackson County, Missouri, announced significant disruptions to its IT systems potentially caused by a ransomware attack. The county detected operational inconsistencies across its digital infrastructure, with some systems rendered inoperative while others remained functional. Specific impacted services included tax payment processing and online portals for property records, marriage license applications, and inmate searches at detention facilities. This disruption necessitated the immediate closure of the Assessment, Collection, and Recorder of Deeds offices at all county locations until further notice. The Kansas City Board of Elections and Jackson County Board of Elections confirmed their systems were unaffected by the outage, with no election-related operations compromised during the April 2 Election Day activities. County officials promptly engaged law enforcement agencies and contracted external IT security specialists to investigate the incident and initiate remediation efforts. Initial public statements emphasized no evidence of data compromise had been identified during the early diagnostic phase.

Jackson County prioritized securing its network against further exploitation while restoration teams worked to resume normal operations. The investigation remained in preliminary stages as of the April 2 announcement, with ransomware considered one potential cause among multiple hypotheses under analysis. Cybersecurity partners conducted comprehensive system reviews to determine the precise origin and mechanism of the disruption. County officials maintained transparency through public updates, acknowledging the operational impact on residents while refraining from speculating about attribution or timelines for full recovery. Ongoing efforts focused on diagnostic validation, infrastructure stabilization, and incremental service restoration, with no additional system compromises reported following the initial containment measures.

Sources

Sources available to members: 2 sources.

CSIDB