CSIDB logo
Incident

City of Tarrant

Incident posture

Attack window
Feb 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 14:09

Linked entities

Victim
City of Tarrant
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Cybercriminals attempted to extort money from a small Alabama city through a ransomware attack that targeted the police department's computer system. Police officials stated that the city will not pay any ransom. City IT contractors were able to shut down the affected server, make repairs, and restore service, preventing the attack from spreading to other municipal departments that operate on separate servers. The attack forced the police department to temporarily revert to filing paper police reports, though other essential computer services like record searches remained operational. An initial social media post claimed all city systems had been shut down, but officials later clarified that the damage was isolated to the police department. An investigation into how the breach occurred is ongoing as the city restarts its systems.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 10, 2025, the City of Tarrant, Alabama, experienced a ransomware attack that targeted the city's digital infrastructure, prompting an immediate response from local officials and IT contractors. According to Police Chief Wendell Major, cybercriminals attempted to extort money from the town by attacking the police department's computer system. The initial public communication from the city suggested a severe situation, with a post on the city's social media account stating, "Due to a ransomware attack, all systems in the City have been shut down." This message indicated a citywide impact and raised immediate concerns about the scope of the incident. However, as the situation developed, officials clarified that the actual damage was more contained than the initial social media post implied, revealing that the attack primarily affected the police department's server rather than the entire municipal network.

The response to the attack was swift and methodical, guided by pre-established cybersecurity protocols. City IT contractors were able to take down the affected server, make necessary repairs, and restore service, effectively neutralizing the immediate threat. Major emphasized that the city's IT protocols were enacted in response to the incident, stating, "You've got to be prepared for this. We just operate like we normally do." This approach allowed the city to contain the attack without paying any ransom, a decision that aligned with broader law enforcement recommendations against complying with cybercriminal demands. The containment strategy was facilitated by the city's network architecture, in which major departments, including the police department, operated on different servers. This segregation prevented the ransomware from spreading across all municipal systems and limited the damage to a single department.

Despite the successful containment, the attack did produce noticeable operational impacts, particularly on the police department's daily functions. The most significant change was that officers were required to file police reports using paper rather than digital systems, reverting to manual record-keeping processes. This shift, while inconvenient, did not halt essential services, as other critical computer functions such as record searches remained operational. The ability to continue accessing these records ensured that the department could maintain core law enforcement capabilities, even amid the disruption. Major noted that the city would continue to investigate the incident to determine how the attackers initially gained access to the police department's system, stating, "We don't know yet how it happened. We just shut it down. We're restarting everything." Efforts to reach Mayor Wayman Newton for additional comments were not immediately successful at the time of reporting.

The incident drew comparisons to a more severe cyberattack that affected the nearby city of Birmingham in March 2024, which had caused widespread operational chaos. That attack had disrupted law enforcement functions by limiting officers' ability to check for stolen vehicles or outstanding warrants, raising serious concerns about public safety and the protection of personal information. Tarrant's experience appeared to avoid a similar crisis, thanks in part to the segmented server structure and the rapid response by IT personnel. The attack highlighted the ongoing vulnerability of municipal government systems to ransomware and other cyber threats, even as it demonstrated the value of preparation and protocol-driven responses in limiting damage.

Sources

Sources available to members: 1 source.

CSIDB