Menu
Browse

Cyber Incident Victim: Tri County Public Safety

Date:

Mar 2021

Location:

United States of America

Summary

A ransomware attack targeted the Tri County Public Safety network, impacting emergency dispatch operations across Albany, Saratoga, and Rensselaer counties. While 911 services in Albany County remained operational, the breach disrupted Computer-Aided Dispatch systems, prompting an overnight response involving vendors and a state cyber incident team. All affected servers and desktops were cleaned, and services were restored using backups. Recovery efforts successfully rebuilt critical infrastructure, with normal operations gradually resuming following mitigation measures.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 15, 2021, at approximately 9:30 PM, the Tri County Public Safety network serving Albany, Saratoga, and Rensselaer Counties in New York experienced a ransomware attack. The Albany County Sheriff’s Office confirmed the incident disrupted operations across the shared public safety infrastructure. Immediate response efforts involved collaboration between the sheriff’s office, technology vendors, and the New York State Division of Homeland Security and Emergency Services (NYDHSES) Office of Counter Terrorism Cyber Incident Response Team. Personnel worked through the night to contain and mitigate the attack’s effects. While critical emergency services such as 911 call response in Albany County remained operational, the attack significantly impacted Computer-Aided Dispatch (CAD) systems used for coordinating emergency responses across the three counties. All network servers and desktop computers connected to the compromised system required comprehensive cleaning to remove malicious artifacts.

Cyber Incident Image

The incident response team prioritized restoring functionality by rebuilding affected systems from preserved backups, a process that enabled gradual service recovery. Officials confirmed no operational data loss occurred due to the availability of these backups, though the attack caused temporary disruptions to dispatch coordination capabilities during the containment period. The sheriff’s office did not disclose whether data exfiltration occurred or identify the ransomware variant involved. Recovery efforts focused on validating system integrity before bringing services back online. By leveraging pre-incident backups and coordinated cybersecurity support, authorities successfully restored critical public safety systems without prolonged service degradation. The attack underscored the operational risks to shared regional infrastructure but demonstrated effective recovery protocols through interagency collaboration and existing contingency planning.

Sources
Sources available to members
1 source