Cyber Incident Victim: Coweta County
Date:
Aug 2018
Location:
United States of America
Summary
A Georgia county government experienced a ransomware attack compromising its information technology servers, disrupting access to critical services including vehicle tags, court operations, and voter registration systems. Hackers demanded $341,000 in bitcoin to restore access. The county restored most affected servers within approximately two weeks, successfully recovering airport, public safety, court, and voter registration systems while continuing recovery efforts for remaining services.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On August 19, 2018, at approximately 6:30 a.m., Coweta County, Georgia, experienced a ransomware attack that compromised its information technology servers. The attack disrupted access to multiple government services, including tag offices, court operations, and other unspecified county functions. Hackers demanded a ransom payment of $341,000 in Bitcoin to restore access to the encrypted systems, marking this as one of several ransomware incidents affecting Atlanta-area government entities during this period. The intrusion immediately impaired routine operations, forcing the county to address service interruptions affecting public-facing departments. Officials publicly confirmed the cyberattack but did not disclose initial technical details about the ransomware variant used or the exact infiltration method. Service limitations persisted for several days as technicians worked to isolate compromised systems and prevent further spread of the malware.

By August 21, 2018—two days after the initial attack—the county restored critical servers supporting airport operations, voter registration systems, court services, and public safety functions. This partial restoration allowed some departments to resume normal operations while recovery efforts continued for remaining affected systems. The county communicated updates through official website statements, confirming that "most" servers were operational again by August 24. No public confirmation was provided regarding whether the ransom was paid or if data exfiltration occurred during the incident. The attack highlighted vulnerabilities in local government infrastructure, following similar ransomware incidents in the region earlier that year. Service restoration timelines indicated approximately five days of significant disruption for non-restored systems, with full recovery details undisclosed in available public reports.
