Cyber Incident Victim: City of Farmington
Date:
Jan 2018
Location:
United States of America
Summary
The City of Farmington experienced a SamSam ransomware attack that encrypted business operations computers, demanding a ransom of 3 bitcoin (over $35,000). Following FBI guidance, the municipality recovered encrypted data without paying the ransom. Critical infrastructure including public safety services, electric utility operations, email systems, and public administration networks remained unaffected, with no extraction of customer or employee personal information. While electronic bill payment and records processing services were temporarily disrupted, most customer-facing business systems were restored. The incident prompted collaboration with federal investigators to determine the attack's origin and a review of security protocols through external contractors. Ransomware impacts were contained without compromising essential services or sensitive data.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 3, 2018, the City of Farmington experienced a ransomware attack that disrupted municipal computer systems. A variant of SamSam ransomware encrypted files across many business operations computers, displaying messages demanding payment of 3 bitcoin (approximately $35,000 at the time) to restore access. The attack specifically targeted business systems supporting customer service operations, forcing the shutdown of electronic bill payment services and records processing functions. City Manager Rob Mayes confirmed the FBI advised against paying the ransom. While the ransomware encrypted files, it did not compromise public administration systems, electric utility operations infrastructure, or city email services. No customer or employee personal information was extracted during the incident, and public safety services continued without interruption throughout the event.

The city initiated recovery efforts immediately following the attack, restoring nearly all affected business systems related to customer service operations. Farmington successfully recovered encrypted data without fulfilling the ransom demand through undisclosed technical means. Concurrently, the city collaborated with the FBI to investigate the attack's origin and methodology, while contracting external cybersecurity experts to review existing security protocols. Operational impacts were contained primarily to temporary disruptions in electronic payment processing and records management. The incident prompted public awareness efforts through press releases highlighting global ransomware trends, including 2016 FBI Internet Crime Complaint Center statistics documenting 2,673 ransomware cases causing $2.4 million in losses. Municipal operations returned to normal following system restoration, with no reported residual effects on critical infrastructure or data integrity.
