Case file · ATLANTA 2018

The 2018 Atlanta ransomware attack: the city that was warned first

Published 2026-09-29 · 4 min read · Missing control: Remediate prior security audit findings

The ransom Atlanta was asked to pay in 2018 was about $51,000. The city refused, and the recovery ended up costing many times that.[1][2][3] This case file covers what the attack shut down, the audit that had warned the city weeks earlier, what prosecutors later charged, and the one control that was missing.

What happened

In January 2018, an audit of the City of Atlanta's information systems found somewhere between 1,500 and 2,000 security weaknesses. The auditors also warned that the teams responsible had grown used to the risk, describing a kind of complacency as the problems piled up.[2]

About two months later, on March 22, 2018, city employees found their files locked. Ransomware known as SamSam had encrypted about 3,789 city computers, a mix of servers and staff workstations.[1] Ransomware scrambles files so they cannot be opened, and the attackers then offer the key for a fee. The note on each machine asked for 0.8 bitcoin per computer, or 6 bitcoin to unlock everything, a sum reported at about $51,000.[1][2]

The effects spread across city life. Court systems went offline, residents could not pay bills online, and the Wi-Fi at Hartsfield-Jackson Atlanta International Airport was switched off as a precaution.[2] Years of police dashboard camera video were permanently lost.[2] Months later, around a third of the city's software programs were still offline or only partly working.[2]

How it worked

SamSam was not the kind of ransomware that spreads on its own through a random email. Prosecutors described a crew that picked its targets, got into their networks, and then encrypted as many machines as possible at once to maximize pressure to pay.[1][4] Their victims were often hospitals, cities and other organizations that cannot afford to be down for long.[4]

The Justice Department's release on the Atlanta charges does not describe exactly how the attackers got in.[1] What is on the record is the state of the network they found: a large backlog of known, unfixed weaknesses that the city's own auditors had just catalogued.[2] Every known flaw left open is a door someone else can try, and a network with a thousand or more of them gives an attacker plenty of choices.

What it cost

The city did not pay the ransom.[1] Instead it spent heavily on recovery. Emergency contracts for outside help came to about $2.7 million in the first weeks, and later estimates rose to $9.5 million.[2] By August 2018, reports described the city's total recovery plans as reaching about $17 million.[3] The figures are estimates and budgets rather than a final audited total.

On December 5, 2018, federal prosecutors in Atlanta announced an indictment charging two Iranian nationals with the attack, alongside charges filed in New Jersey over the wider SamSam campaign.[1][4] Prosecutors say the pair built SamSam and used it against Atlanta and many other victims. The charges are allegations; the defendants have not been tried in the United States.[1]

The missing control

The missing control: fixing the findings from past security audits, on a deadline, with someone accountable for each one.

An audit only lowers risk when its findings get fixed. Atlanta's January 2018 review had already named the problem: a large, aging pile of known weaknesses that nobody was clearing.[2] Working that list down, starting with the most severe items on systems reachable from the internet, would have left attackers far fewer ways in. Tracking progress and reporting it to leadership would also have made it harder for the risk to be treated as normal. The ransom note was the result; the backlog was the cause.

What to do in your business

Watch the case
The ransom Atlanta refused, and the audit it ignoredDrops 2027-01-10
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More patching and monitoring cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. U.S. Attorney's Office, Northern District of Georgia: Atlanta U.S. Attorney charges Iranian nationals for City of Atlanta ransomware attack
  2. Wikipedia: Atlanta government ransomware attack
  3. Bitdefender: At $17 million, Atlanta network recovery six times more expensive than estimated
  4. NPR: Georgia charges Iranians in ransomware attack on Atlanta