Cyber Incident Victim: Tri County Sheriff Dispatch
Date:
Mar 2021
Location:
United States of America
Summary
A ransomware attack targeted the Tri County Public Safety network, impacting emergency dispatch systems across multiple counties. While 911 services remained operational in Albany County, Computer-Aided Dispatch systems were compromised, requiring all servers and desktops to be cleaned. The sheriff's office collaborated with vendors and a state cyber incident response team overnight to mitigate the attack, successfully restoring services through backups. Systems were rebuilt, and operations gradually resumed following the containment efforts.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 16, 2021, at approximately 9:30 PM, the Tri County Public Safety network serving Albany, Saratoga, and Rensselaer Counties in New York experienced a ransomware attack. The Albany County Sheriff’s Office confirmed the incident, noting that their personnel collaborated with external vendors and the New York Division of Homeland Security and Emergency Services (NYDHSES) Office of Counter Terrorism Cyber Incident Response Team throughout the night to mitigate the attack. Immediate response efforts focused on containment and system restoration, with no disruption reported to 911 emergency call services in Albany County. The attack specifically compromised Computer Aided Dispatch (CAD) systems, which are critical for coordinating emergency responses and dispatching resources. All affected servers and desktops underwent comprehensive cleaning procedures to remove malicious artifacts and restore operational integrity.

Officials utilized existing backups to rebuild compromised systems, enabling a phased restoration of services. The incident did not extend beyond the CAD infrastructure, preserving core emergency communication functions. No evidence suggested exfiltration of sensitive data or additional collateral damage to adjacent networks. Recovery operations prioritized reactivating dispatch capabilities while maintaining public safety protocols. The collaboration with state cybersecurity experts and technology vendors facilitated a coordinated technical response, though the specific ransomware variant and initial attack vector were not disclosed publicly. Service restoration progressed systematically following the overnight mitigation work, with normal operations resuming after systems were validated as secure. The incident underscored the operational reliance on digital dispatch systems while highlighting the resilience of segregated emergency communication networks during cyber disruptions.
