CSIDB logo
Incident

Wheat Ridge, Colorado, USA (Jefferson County)

Incident posture

Attack window
Aug 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-08-28 14:53

Linked entities

Victim
Wheat Ridge, Colorado, USA (Jefferson County)
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Aug 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack encrypted municipal data and computer systems in the City of Wheat Ridge, prompting a $5 million ransom demand from an overseas threat actor. The city refused payment and initiated internal recovery efforts to restore operations. The incident forced the closure of city hall, causing significant disruption to municipal services during the response period.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around August 29, 2022, the City of Wheat Ridge, a Denver suburb, experienced a ransomware attack that disrupted municipal operations and forced the closure of city hall. A foreign-based ransomware group encrypted the city’s data and computer systems, rendering them inaccessible. The attackers demanded a $5 million ransom payment in exchange for decrypting the compromised systems and restoring access. City officials publicly refused to pay the ransom, opting instead to dedicate resources toward independently restoring operations. The attack caused significant operational disruptions, particularly impacting city hall functions, though specific departmental effects were not detailed in available reports. Municipal staff initiated recovery efforts without capitulating to the extortion attempt.

The incident’s primary immediate consequence was the shutdown of city hall facilities, halting routine municipal services and public access. No confirmed data theft or exfiltration was disclosed in initial reports, focusing impact assessments on operational paralysis rather than data compromise. Recovery priorities centered on rebuilding internal systems without external decryption assistance, though restoration timelines and technical methodologies remained unspecified. Financial losses stemmed from operational downtime and remediation costs rather than ransom payments. The city’s defiance established a public stance against negotiating with ransomware operators, though long-term recovery challenges were not enumerated in available documentation. Municipal operations resumed gradually following system restoration efforts.

Sources

Sources available to members: 2 sources.

CSIDB