CSIDB logo
Incident

Pennsylvania Senate Democrats

Incident posture

Attack window
Mar 2017
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-08 00:00

Linked entities

Victim
Pennsylvania Senate Democrats
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Pennsylvania Senate Democrats experienced a ransomware attack that encrypted their computer network data, locking senators and employees out of their systems. Hackers demanded payment in exchange for a decryption key, though the specific ransom amount and any potential political motive were not disclosed. The Democratic caucus, operating on a separate network from other state agencies and Republican counterparts, collaborated with law enforcement and Microsoft to resolve the incident, with no evidence of broader compromise. The attackers' identity and whether data backups existed remained unclear, while the FBI's potential involvement was under consideration.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 3, 2017, Pennsylvania Senate Democrats disclosed a ransomware attack that had compromised their computer network, locking senators and employees out of systems since the early morning hours of Friday, March 2. The attack involved malware that encrypted critical data, with attackers demanding payment in exchange for a decryption key. Senate Democratic Leader Jay Costa confirmed the incident in a public statement, noting collaboration with law enforcement agencies and Microsoft to restore operations. The attackers’ identity, specific ransom amount, and payment method remained undisclosed by officials. No evidence suggested the compromise extended beyond the Democratic caucus’s isolated network in Harrisburg, with state officials confirming no impact on Republican-operated systems or other government agencies.

The incident disrupted legislative operations but did not reveal a clear political motive or specific targeting rationale. A state official, speaking anonymously, emphasized the uncertainty surrounding the attackers’ intentions. The Pennsylvania Senate Democrats’ spokesperson, Stacey Witalec, declined to confirm whether backups existed or whether the perpetrators had communicated any ideological demands. The FBI’s potential involvement remained unconfirmed at the time of reporting, with agency representatives reviewing whether they had been formally engaged. Recovery efforts focused on system restoration without validating whether ransom negotiations occurred, leaving the operational and financial consequences unresolved in initial disclosures.

Sources

Sources available to members: 1 source.

CSIDB