CSIDB logo
Incident

Virginia Sex Offender and Crimes Against Children Registry

Incident posture

Attack window
Apr 2017
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-07 00:00

Linked entities

Victim
Virginia Sex Offender and Crimes Against Children Registry
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A malware infection impacted Virginia State Police servers, disrupting email services and preventing updates to the Sex Offender and Crimes Against Children Registry. The department collaborated with a state technology agency and a cybersecurity firm to remove the malware, restoring functionality by the end of the week. While field operations and other critical systems—including traffic enforcement, criminal investigations, and background checks—remained unaffected, officers were temporarily unable to modify registry data. Public access to the online registry continued uninterrupted during the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around April 26, 2017, malware infected servers operated by the Virginia State Police (VSP), disrupting critical departmental functions. The infection prevented updates to the Virginia Sex Offender and Crimes Against Children Registry (SOR) database and website, hindering law enforcement's ability to maintain current offender records. Additionally, the malware forced the shutdown of VSP's internal email system, though telephone communications remained operational for staff. The incident began on Wednesday, with VSP personnel engaging the Virginia Information Technologies Agency (VITA) and cybersecurity contractor Northrop Grumman to address the infection. Remediation efforts concluded by Thursday afternoon, restoring normal operations by the end of the week. A VSP spokesperson confirmed the malware did not compromise field operations or public access to the SOR website, which remained viewable throughout the incident. No evidence suggested unauthorized access to registry data or exfiltration of sensitive information.

The malware exclusively impacted systems supporting email services and SOR updates, leaving other VSP functions unaffected. Systems handling traffic crash investigations, traffic enforcement, criminal investigations, firearms transactions, and background checks continued normal operations. The spokesperson declined to disclose technical details about the malware variant or initial infection vector. While the incident caused temporary operational delays, it resulted in no permanent data loss or systemic compromise. This contrasts with a separate December 2016 ransomware incident at Texas’s Cockrell Hill Police Department, which caused irreversible evidence loss due to backup failures. Virginia’s coordinated response with VITA and Northrop Grumman facilitated swift containment without cascading effects on other public safety infrastructure.

Sources

Sources available to members: 1 source.

CSIDB