Cyber Incident Victim: Champaign County Clerk
Date:
Nov 2022
Location:
United States of America
Summary
The Champaign County Clerkâs office experienced repeated cyber-attacks targeting its network and servers, primarily in the form of D-DOS incidents over approximately one month, which degraded server performance but did not compromise data or election integrity. Enhanced security measures and IT team interventions successfully mitigated these attacks, maintaining website functionality and ensuring no unauthorized access to sensitive information occurred throughout the incident period.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The Champaign County Clerk's office experienced sustained cyber-attacks targeting its network infrastructure and servers throughout October 2022, with incidents continuing into early November. These attacks consisted of repeated distributed denial-of-service (D-DOS) attempts directed at the office's public-facing website, designed to overwhelm systems and disrupt normal operations. The malicious activity persisted for approximately one month prior to the November 8 public disclosure, during which attackers made multiple efforts to compromise digital assets. Server performance degradation occurred as a direct consequence of these intrusion attempts, though critical systems maintained operational continuity throughout the incident period. Election-related infrastructure remained unaffected despite the targeting occurring during election season, with no evidence suggesting specific voter data or ballot systems were breached.

County Clerk IT personnel implemented reinforced security measures to counter the ongoing attacks, successfully preventing any full system compromise or unauthorized data access. Continuous monitoring and rapid response protocols enabled the technical team to mitigate each D-DOS attempt before service interruptions could occur. Public access to the Clerk's website remained available throughout the incident due to these defensive actions, preserving constituent services and information dissemination capabilities. Officials confirmed no sensitive data exfiltration occurred across any county systems, maintaining the integrity of both operational records and election management infrastructure. The sustained defensive effort resulted in complete attacker failure to achieve persistent access or disrupt critical governmental functions despite the prolonged assault campaign.
