The 2018 Atlanta ransomware attack: the city that was warned first
The ransom Atlanta was asked to pay in 2018 was about $51,000. The city refused, and the recovery ended up costing many times that.[1][2][3] This case file covers what the attack shut down, the audit that had warned the city weeks earlier, what prosecutors later charged, and the one control that was missing.
What happened
In January 2018, an audit of the City of Atlanta's information systems found somewhere between 1,500 and 2,000 security weaknesses. The auditors also warned that the teams responsible had grown used to the risk, describing a kind of complacency as the problems piled up.[2]
About two months later, on March 22, 2018, city employees found their files locked. Ransomware known as SamSam had encrypted about 3,789 city computers, a mix of servers and staff workstations.[1] Ransomware scrambles files so they cannot be opened, and the attackers then offer the key for a fee. The note on each machine asked for 0.8 bitcoin per computer, or 6 bitcoin to unlock everything, a sum reported at about $51,000.[1][2]
The effects spread across city life. Court systems went offline, residents could not pay bills online, and the Wi-Fi at Hartsfield-Jackson Atlanta International Airport was switched off as a precaution.[2] Years of police dashboard camera video were permanently lost.[2] Months later, around a third of the city's software programs were still offline or only partly working.[2]
How it worked
SamSam was not the kind of ransomware that spreads on its own through a random email. Prosecutors described a crew that picked its targets, got into their networks, and then encrypted as many machines as possible at once to maximize pressure to pay.[1][4] Their victims were often hospitals, cities and other organizations that cannot afford to be down for long.[4]
The Justice Department's release on the Atlanta charges does not describe exactly how the attackers got in.[1] What is on the record is the state of the network they found: a large backlog of known, unfixed weaknesses that the city's own auditors had just catalogued.[2] Every known flaw left open is a door someone else can try, and a network with a thousand or more of them gives an attacker plenty of choices.
What it cost
The city did not pay the ransom.[1] Instead it spent heavily on recovery. Emergency contracts for outside help came to about $2.7 million in the first weeks, and later estimates rose to $9.5 million.[2] By August 2018, reports described the city's total recovery plans as reaching about $17 million.[3] The figures are estimates and budgets rather than a final audited total.
On December 5, 2018, federal prosecutors in Atlanta announced an indictment charging two Iranian nationals with the attack, alongside charges filed in New Jersey over the wider SamSam campaign.[1][4] Prosecutors say the pair built SamSam and used it against Atlanta and many other victims. The charges are allegations; the defendants have not been tried in the United States.[1]
The missing control
The missing control: fixing the findings from past security audits, on a deadline, with someone accountable for each one.
An audit only lowers risk when its findings get fixed. Atlanta's January 2018 review had already named the problem: a large, aging pile of known weaknesses that nobody was clearing.[2] Working that list down, starting with the most severe items on systems reachable from the internet, would have left attackers far fewer ways in. Tracking progress and reporting it to leadership would also have made it harder for the risk to be treated as normal. The ransom note was the result; the backlog was the cause.
What to do in your business
- Pull out your last security review. Whether it was a formal audit, an insurance questionnaire or a note from your IT provider, list every issue it raised.
- Give each finding an owner and a date. Put the list in a simple spreadsheet, with one name and one due date per item, and review it monthly.
- Fix internet-facing problems first. Anything that can be reached from outside, such as remote access, your website or email, goes to the top of the list.
- Retire software that no longer gets updates. Old versions of Windows and other programs stop getting security fixes; plan and budget to replace them.
- Keep offline backups and test them. Keep at least one backup copy disconnected from your network, and practice restoring it so ransomware cannot hold you hostage.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How a small business keeps software and devices patched, and why default passwords must go
- What caused the Equifax breach? An unpatched website and an expired certificate
- How the Capital One breach happened: one misconfigured cloud firewall
- What happened to Knight Capital: $460 million lost in 45 minutes
- How WannaCry hit the NHS: the fix existed 2 months before the attack
- How the Heartland breach happened: 130 million cards and an informant
- How the HSE cyber attack happened: one spreadsheet and 8 weeks of ignored alerts
- Every patching and monitoring control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- U.S. Attorney's Office, Northern District of Georgia: Atlanta U.S. Attorney charges Iranian nationals for City of Atlanta ransomware attack
- Wikipedia: Atlanta government ransomware attack
- Bitdefender: At $17 million, Atlanta network recovery six times more expensive than estimated
- NPR: Georgia charges Iranians in ransomware attack on Atlanta