Cyber Incident Victim: Miller County
Date:
Oct 2022
Location:
United States of America
Summary
A ransomware attack disrupted operations across multiple county offices in Arkansas, including Miller County, impacting systems managed by Apprentice Information Systems. The breach compromised workstations in the treasurer, clerk, and judge's offices, necessitating manual processes such as handwritten record-keeping while systems were wiped and reloaded; although firewalls protected core infrastructure, recovery timelines remained unclear. The incident affected 55 counties, causing widespread temporary closures and offline services.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
A ransomware attack impacted Miller County, Arkansas, along with 54 other Arkansas counties, around October 23, 2022. The incident forced multiple county offices offline or into temporary closures due to compromised systems. All affected counties relied on Apprentice Information Systems for their online server infrastructure. In Miller County, the attack specifically targeted the County Treasurer’s Office, County Clerk’s Office, and County Judge’s Office. Attackers compromised all workstations across these offices despite existing firewall protections, necessitating a full system wipe and reload. The breach disrupted standard operations for approximately two weeks before public acknowledgment on November 6. No data theft or encryption specifics were disclosed, but the ransomware’s impact required manual workarounds.

County Treasurer Teresa Reed confirmed the firewall prevented deeper system infiltration but acknowledged all workstations required remediation. Her office resorted to handwritten record-keeping during recovery, significantly slowing administrative processes. No timeline existed for restoring computer systems as of November 6, leaving operations dependent on manual methods indefinitely. Reed publicly requested patience from residents, emphasizing staff efforts to maintain services despite constraints. The incident highlighted statewide vulnerabilities through the shared third-party vendor but yielded no attribution details or ransom demands in available reports. Recovery efforts focused on rebuilding compromised endpoints rather than paying extortion, based on the described remediation actions.
