May 22, 2019 By David Bisson 2 min read

Many of the city of Baltimore’s public services remain offline two weeks after the municipality fell victim to a ransomware attack.

On May 21, NPR noted that the ransomware attack, which is believed to have occurred on May 7, continues to affect several of Baltimore’s public services. City employees still can’t use their government-issued computers or email accounts to get work done. Instead, employees have been using their personal laptops and email accounts or even reverting back to paper-based processes to conduct official government business.

According to Ars Technica, the infection disrupted the city’s ability to receive payments for water bills, parking tickets and citations for traffic violations as well. It also affected the Baltimore Police Department’s network of surveillance cameras, but had no effect on the city’s emergency systems.

City officials said they don’t intend to pay the ransom of 13 bitcoins — currently worth more than $100,000 — despite the fact that the offending malware sample, a variant of RobbinHood, currently has no publicly available decryptors. Officials also indicated that they will continue to work with the FBI and Secret Service, who are both investigating the incident.

Not the First Cyberattack on a Municipality

This isn’t the first time that a municipality has fallen victim to a ransomware attack. Back in March 2018, for instance, the city of Atlanta suffered an infection that disrupted employees’ access to the government network and affected public payment systems. As the Atlanta Journal-Constitution reported, the attack could cost Atlanta taxpayers as much as $17 million.

Around that same time, Baltimore suffered its own infection that shut down the city’s 911 emergency dispatch system, noted the Baltimore Sun. This attack came a little more than a year before WITN broke the news of a RobbinHood infection affecting the city government in Greenville, North Carolina.

How to Defend Against a Ransomware Attack

Organizations are increasingly reporting ransomware attacks and refusing to pay ransoms. Security professionals can join this ongoing fight by putting prevention first and developing a layered defensive strategy that makes use of anti-malware tools, anti-spam filters and security awareness training. Proper instruction should teach all employees — from entry-level to C-suite — about some of the most common social engineering techniques employed by digital attackers today.

More from

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

4 ways to bring cybersecurity into your community

4 min read - It’s easy to focus on technology when talking about cybersecurity. However, the best prevention measures rely on the education of those who use technology. Organizations training their employees is the first step. But the industry needs to expand the concept of a culture of cybersecurity and take it from where it currently stands as an organizational responsibility to a global perspective.When every person who uses technology — for work, personal use and school — views cybersecurity as their responsibility, it…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today