Menu
Browse

Cyber Incident Victim: Pennsylvania Senate Democrats

Date:

Mar 2017

Location:

United States of America

Summary

The Pennsylvania Senate Democrats experienced a ransomware attack that encrypted their computer network data, locking senators and employees out of their systems. Hackers demanded payment in exchange for a decryption key, though the specific ransom amount and any potential political motive were not disclosed. The Democratic caucus, operating on a separate network from other state agencies and Republican counterparts, collaborated with law enforcement and Microsoft to resolve the incident, with no evidence of broader compromise. The attackers' identity and whether data backups existed remained unclear, while the FBI's potential involvement was under consideration.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 3, 2017, Pennsylvania Senate Democrats disclosed a ransomware attack that had compromised their computer network, locking senators and employees out of systems since the early morning hours of Friday, March 2. The attack involved malware that encrypted critical data, with attackers demanding payment in exchange for a decryption key. Senate Democratic Leader Jay Costa confirmed the incident in a public statement, noting collaboration with law enforcement agencies and Microsoft to restore operations. The attackers’ identity, specific ransom amount, and payment method remained undisclosed by officials. No evidence suggested the compromise extended beyond the Democratic caucus’s isolated network in Harrisburg, with state officials confirming no impact on Republican-operated systems or other government agencies.

Cyber Incident Image

The incident disrupted legislative operations but did not reveal a clear political motive or specific targeting rationale. A state official, speaking anonymously, emphasized the uncertainty surrounding the attackers’ intentions. The Pennsylvania Senate Democrats’ spokesperson, Stacey Witalec, declined to confirm whether backups existed or whether the perpetrators had communicated any ideological demands. The FBI’s potential involvement remained unconfirmed at the time of reporting, with agency representatives reviewing whether they had been formally engaged. Recovery efforts focused on system restoration without validating whether ransom negotiations occurred, leaving the operational and financial consequences unresolved in initial disclosures.

Sources
Sources available to members
1 source