CSIDB logo
Incident

Miller County Government

Incident posture

Attack window
Oct 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-16 00:00

Linked entities

Victim
Miller County Government
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack disrupted operations across multiple county offices in Arkansas, including Miller County, impacting systems managed by Apprentice Information Systems. The breach compromised workstations in the treasurer, clerk, and judge's offices, necessitating manual processes such as handwritten record-keeping while systems were wiped and reloaded; although firewalls protected core infrastructure, recovery timelines remained unclear. The incident affected 55 counties, causing widespread temporary closures and offline services.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

A ransomware attack impacted Miller County, Arkansas, along with 54 other Arkansas counties, around October 23, 2022. The incident forced multiple county offices offline or into temporary closures due to compromised systems. All affected counties relied on Apprentice Information Systems for their online server infrastructure. In Miller County, the attack specifically targeted the County Treasurer’s Office, County Clerk’s Office, and County Judge’s Office. Attackers compromised all workstations across these offices despite existing firewall protections, necessitating a full system wipe and reload. The breach disrupted standard operations for approximately two weeks before public acknowledgment on November 6. No data theft or encryption specifics were disclosed, but the ransomware’s impact required manual workarounds.

County Treasurer Teresa Reed confirmed the firewall prevented deeper system infiltration but acknowledged all workstations required remediation. Her office resorted to handwritten record-keeping during recovery, significantly slowing administrative processes. No timeline existed for restoring computer systems as of November 6, leaving operations dependent on manual methods indefinitely. Reed publicly requested patience from residents, emphasizing staff efforts to maintain services despite constraints. The incident highlighted statewide vulnerabilities through the shared third-party vendor but yielded no attribution details or ransom demands in available reports. Recovery efforts focused on rebuilding compromised endpoints rather than paying extortion, based on the described remediation actions.

Sources

Sources available to members: 1 source.

CSIDB