Cyber Incident Victim: Rockdale County
Date:
Feb 2020
Location:
United States of America
Summary
A ransomware attack compromised multiple servers in Rockdale County after an employee opened a malicious email attachment, triggering an internal alert system that prompted immediate response efforts. The incident disrupted phone lines, internet, and email services with sporadic connectivity, necessitating a full server shutdown for investigation. County operations were impacted, including the Water Resources department's inability to process payments, though affected customers were granted a grace period for bills due during the outage. The extent of system damage remained unclear during initial triage and troubleshooting.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On February 7, 2020, Rockdale County experienced a ransomware attack that compromised multiple county servers, disrupting operations and public services. The incident began when an employee opened a malicious email attachment containing a computer virus, enabling attackers to infiltrate the system. Rockdale County Technology Services confirmed that up to nine servers were affected by the breach. The county’s internal alert system detected the unauthorized access, prompting immediate triage and troubleshooting efforts by technology staff. Officials announced a planned shutdown of all servers later that day to investigate the full scope of the infiltration, warning residents to expect sporadic interruptions to phone lines, internet connectivity, and email services throughout the disruption. The technology department publicly communicated these developments via a Facebook post but acknowledged the full extent of the damage remained unknown at the time.

The attack had tangible operational consequences, particularly for Rockdale Water Resources, which lost the ability to process customer payments on the day of the incident. The county assured residents that bills due on February 7 would receive a grace period, with specifics to be determined after systems were restored. No ransom demands or threat actor details were disclosed in available reports. County officials focused on containment through server shutdowns and diagnostic procedures while maintaining limited public communications through social media updates. Service restoration timelines and final impact assessments were not provided in the immediate aftermath, leaving the resolution process ongoing as of the initial reporting date.
