Cyber Incident Victim: Georgia Motor Carrier Compliance Division
Date:
Jul 2019
Location:
United States of America
Summary
A ransomware attack targeted multiple state law enforcement agencies, including the Georgia Motor Carrier Compliance Division, disrupting operations by compromising computer networks. The infection originated on a field laptop before spreading to other workstations, prompting authorities to shut down the entire network to contain the threat. This forced personnel to rely solely on radio dispatch and phone communications for law enforcement activities, significantly hindering their ability to access digital information systems. While core duties remained possible, the incident caused major operational challenges. Multiple IT specialists and federal investigators collaborated to address the attack, though the specific ransomware demands were not publicly disclosed during the initial response.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 25, 2019, the Georgia State Patrol (GSP) detected a ransomware attack originating from a field laptop, triggering a multi-agency cybersecurity incident. Within 24 hours of initial detection, the malicious activity spread to additional workstations across three state law enforcement agencies: the Georgia State Patrol, State Capitol Police, and the Motor Carrier Compliance Division (identified as the commercial enforcement division in reports). Officials disabled the entire network serving these agencies as a containment measure, forcing all affected systems offline. The ransomware disrupted normal operations by blocking access to computer networks essential for information research and administrative functions. Law enforcement personnel transitioned to radio dispatch communications and telephone lines to maintain critical operations, though the network shutdown caused significant workflow interruptions. No specific ransom demands or payment instructions were publicly disclosed in initial reports.

The attack caused major operational disruptions but did not prevent officers from performing core law enforcement duties. Response efforts involved coordinated investigations by multiple IT agencies and cybersecurity specialists, with the FBI formally joining the investigation by July 28. Network systems remained offline through at least July 27 as containment and forensic analysis continued. The incident specifically impaired officers' ability to conduct database queries, process digital records, and access networked resources required for routine operations. No data theft or secondary impacts beyond the ransomware encryption were confirmed in available reporting. Restoration timelines and technical specifics regarding the ransomware variant were not disclosed during the initial response phase.
