The City of Atlanta was hit by SamSam ransomware, which disrupted a wide range of municipal services. The city chose not to pay the ransom. Some systems remained offline for weeks, and city staff returned to paper forms.
What happened
- The attack, disclosed on 22 March 2018, affected systems used for bill payments, court services, and police reports.
- The attackers demanded a ransom in Bitcoin, reported to be around $51,000.
- Recovery took weeks, and costs were reported to run into millions of dollars.
- In November 2018 the US Department of Justice indicted two Iranian men over the SamSam campaign, which targeted Atlanta and many other organisations.
Why it mattered
It was one of the most disruptive ransomware attacks on a US city at the time, and it showed the risks facing local government services. Many other US cities and public bodies were hit by ransomware in the years that followed.
Lessons for organisations
Maintain tested offline backups, reduce exposure of remote access services, and patch systems promptly. Local and public bodies should plan how to deliver essential services if IT systems are unavailable.
Sources: BleepingComputer, CNBC
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.