CSIDB logo
Incident

Town of Apex

Incident posture

Attack window
Jul 2024
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-29 18:33

Linked entities

Victim
Town of Apex
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jul 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Town of Apex experienced a cybersecurity incident after its IT department identified system irregularities, prompting immediate containment actions and an investigation involving the North Carolina Joint Cybersecurity Task Force and federal law enforcement. Emergency services remained fully operational throughout due to existing contingency plans, though some systems were proactively taken offline, disrupting online utility payments, new service setups, and building permit inspections. Most operations continue under normal hours with limited capacity as technical experts work to restore affected systems securely. The municipality is collaborating with cybersecurity professionals and legal counsel to resolve the situation while exploring alternative payment solutions for impacted services.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On the morning of July 2, 2024, the Town of Apex Information Systems Technology Department identified irregularities within municipal systems, prompting an immediate response to secure the environment and contain a suspected cybersecurity incident. The town initiated an internal investigation while simultaneously engaging the North Carolina Joint Cybersecurity Task Force, a collaborative unit comprising cybersecurity specialists from the NC National Guard, NCLGISA Cybersecurity Strike Team, NC Emergency Management, and NC Department of IT. Federal law enforcement agencies were notified of the incident as part of standard reporting protocols. Emergency preparedness plans were activated to maintain continuity of critical services, with town officials confirming that life safety operations—including all emergency response functions—remained fully operational throughout the event. Information technology personnel worked alongside external cybersecurity experts to methodically restore affected systems, prioritizing secure recovery processes while maintaining municipal operations under modified conditions.

The incident caused significant disruptions to specific municipal services, particularly those reliant on online platforms. Utility billing systems were taken offline as a precautionary measure, suspending all electronic payment capabilities and requiring in-person transactions at town offices. Staff explored alternative payment processing solutions while accommodating potential billing delays through customer service interventions. Building permit operations shifted to telephone-based coordination, with inspection requests requiring voicemail submissions before daily deadlines. Despite these service limitations, town government maintained standard operating hours with reduced capacity across non-essential functions. Municipal officials committed to ongoing collaboration with technical experts, legal counsel, and cybersecurity professionals to resolve the situation, emphasizing transparency through dedicated website updates while refraining from speculating about incident origins or potential data compromises during the active investigation phase.

Sources

Sources available to members: 2 sources.

CSIDB