Cyber Incident Victim: City of Ellensburg
Date:
Dec 2020
Location:
United States of America
Summary
The City of Ellensburg experienced a ransomware attack that disrupted access to the majority of its network drives and data, severely impacting municipal operations across all departments. Critical services including utility billing, administrative functions, and financial systems were rendered inoperable due to the encryption of data. Officials confirmed the incident as ransomware but did not disclose the specific variant involved or whether a ransom demand was issued, leaving restoration timelines and recovery methods unclear while systems remained offline.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In December 2020, the City of Ellensburg, Washington, publicly confirmed it had fallen victim to a ransomware cyberattack. The attack rendered the majority of the city’s network drives and internal data inaccessible, disrupting operations across all municipal departments. City officials did not disclose the specific strain of ransomware used in the attack or whether the attackers had issued a financial ransom demand. The incident caused immediate operational paralysis, with critical systems including utility billing, administrative services, and financial services becoming unavailable. This widespread disruption hindered the city’s ability to process payments, manage financial records, and conduct routine administrative functions. No details were provided regarding the initial attack vector, the duration of system compromise prior to detection, or whether data exfiltration occurred alongside the encryption of files.

The ransomware’s impact extended beyond technical systems to essential public services, though the city did not specify whether emergency response systems or public safety operations were affected. Municipal employees faced significant challenges in performing daily tasks due to the loss of access to network resources and data repositories. The city did not release information about containment measures, recovery timelines, or whether external cybersecurity experts were engaged to assist. No public statements addressed potential impacts on residents’ personal data or the long-term financial consequences of the disruption. The incident highlighted vulnerabilities in local government infrastructure but yielded no confirmed attribution to any specific threat actor or group based on the available public disclosures.
