2018 Atlanta cyberattack
|Date||22 March 2018|
|Location||Atlanta, Georgia, United States|
|Theme||Ransomware encrypting files with $51,000 demand (via bitcoin)|
Multiple municipal services down, including databases and wifi.|
Years' worth of data destroyed.
City spends $2.7 million in recovering services
The City of Atlanta, Georgia was the subject of a massive cyberattack which began in March 2018. The attack was recognized by the City of Atlanta on Thursday, March 22, 2018. The city has publicly acknowledged it was a ransomware attack.
Many city services and programs were affected by the attack, including online services for citizens to pay bills and request utility service. The effects of the incident were so widespread that officials resorted to completing paper forms by hand.
The attack was notable for the extent of services affected and the duration of service outages, as well as the importance of Atlanta as a major American economic and transportation hub.
Approach and Attack
Leading up to the attack, the Atlanta government was criticized for a lack of spending on upgrading its IT infrastructure, leaving multiple vulnerabilities open to attack. In fact, a January 2018 audit found 1,500 to 2,000 vulnerabilities in the city's systems, and suggested that the number of vulnerabilities had grown so large that workers grew complacent. The virus used to attack the city was the SamSam Ransomware, which differs from other Ransomware in that it does not rely on phishing, but rather utilizes a brute-force attack to guess weak passwords until one breaks open. It is known to target weaker IT infrastructures and servers. The ransomware has prominently been behind attacks on medical and government organizations since its discovery in 2016, with previous attacks on targets ranging from small towns such as Farmington, New Mexico to the Colorado Department of Transportation and the Erie County Medical Center. It can also bypass antivirus software. To date, the identity of the SamSam hackers remains unknown, but they have been described as "opportunistic".
On March 22, at 5:40 AM, the Department of Atlanta Information Management first learned of outages on various internal and customer applications “including some applications customers use to pay bills or access court related information,” according to Richard Cox, the city’s interim Chief of Operations. Soon afterward, the city shut down many of its digital services in an attempt to control the situation, including its court system database and the wi-fi at Hartsfield–Jackson Atlanta International Airport. The city eventually identified it as a ransomware attack.
Aftermath and Recovery efforts
This hack was notable as it was the largest successful breach of security for a major American city by ransomware, potentially affecting up to 6 million people. Following the attack, the city of Atlanta cooperated with the FBI, Department of Homeland Security, and Secret Service and hired security firms such as SecureWorks to investigate, and many government computers were advised to stay powered off until 5 days later.
Though the city declared that there was little to no evidence that personal data had been compromised, later studies show that the breach was worse than originally estimated. In June 2018, it was estimated that a third of the software programs used by the city remained offline or partially disabled. In addition, many legal documents and police dashcam video files were permanently deleted, though the police department was able to restore access to all its investigation files. For a while, residents were forced to pay their bills and forms by paper.
In response to this hack, Atlanta devoted $2.7 million to contractors in order to recover, but later estimated it would need $9.5 million.
- "Atlanta, GA : Ransomware Cyberattack Information". www.atlantaga.gov.
- Press, The Associated (23 March 2018). "Atlanta City Computer Network Remains Hobbled by Cyberattack" – via NYTimes.com.
- "Atlanta officials warn cyber attack may compromise sensitive data".
- Kearney, Laila. "Atlanta ransomware attack throws city services into disarray".
- CNN, Kimberly Hutcherson,. "Six days after a ransomware cyberattack, Atlanta officials are filling out forms by hand".
- Blinder, Alan; Perlroth, Nicole (27 March 2018). "A Cyberattack Hobbles Atlanta, and Security Experts Shudder" – via NYTimes.com.
- Freed, Benjamin (April 24, 2018). "Atlanta was not prepared to respond to a ransomware attack". StateScoop. Retrieved July 18, 2018.
- Crowe, Jonathan (March 2018). "City of Atlanta Hit with SamSam Ransomware: 5 Key Things to Know". Barkley vs Malware. Barkley Protects, Inc. Retrieved July 18, 2018.
- "SamSam ransomware attacks have earned nearly $850,000". CSO Online. IDG. March 23, 2018. Retrieved July 18, 2018.
- Poon, Linda (March 30, 2018). "Why Are Cities So Vulnerable to Cyber Attack?". Citylab.com. Retrieved July 18, 2018.
- "Atlanta officials reveal worsening effects of cyber attack". Thomson Reuters. June 6, 2018. Retrieved July 18, 2018.
- Vaas, Lisa (June 8, 2018). "Atlanta ransomware attack destroyed years of police dashcam video". Naked Security. Sophos.