Feb 20, 2020 - Technology

Local governments' ransomware problem drags on

Illustration: Aïda Amer/Axios

At least 21 state and municipal government agencies in the United States this year were locked out of their own records and computer systems until they paid up, according to data disclosed to Axios by security company Emsisoft.

Why it matters: Ransomware attacks are among the most dangerous cybersecurity risks facing businesses and governments, Brett Callow, a threat analyst with Emsisoft, said. The threats cost the U.S. roughly $7.5 billion last year, the company estimates.

  • They work like this: The attackers encrypt a target organization's files so it is unable to operate computers, email or websites unless they pay.
  • Attackers are upping the danger with a new trend: Stealing their victims' data as leverage for payment, which began at the end of last year, Callow said.

What's happening: Local governments have succumbed to ransomware at a rate of one every other day since the start of 2020, Emsisoft estimates. Those attacks have resulted in interrupted 911 emergency services, closed schools, offline surveillance systems and states unable to issue or renew driver's licenses.

  • Yes, but: Callow said "there has been no noticeable increase at the rates at which governments have been hit," and this year's rate seems to be consistent with last year.
  • Ransomware attacks historically spike from March to May and then peak through the summer months, he said.
  • Emsisoft isn't sure why those spikes happen, but they are "possibly tied to Easter and summer vacation times" when fewer people are handling more emails that could include suspect attachments, Callow said.

Catch up quick: At least 10 police departments were targeted in 2019 and 2020, including the NYPD, reported in November, whose fingerprint database was hit.

  • Other targets reported this year include the Contra Costa County Library in California, the Albany County Airport Authority in New York, the New Mexico Public Regulation Commission, the Ernest N. Morial New Orleans Convention Center, the North Miami Beach Police Department, Belvidere City Hall in Illinois and Volusia County libraries in Florida.
  • In 2019, courts across Georgia had to reenter civil and criminal records because of an attack. They were among 113 government entities targeted, per Emsisoft.

Between the lines: "Organizations usually don't disclose how frequently they're attacked or what they're attacked by," Callow noted. "We only find out about the ransomware cases because they're very hard to hide, because they are so disruptive."

The bottom line: "It used to be said that backups are the best defense against ransomware," Callow said. "But, that's the not the case anymore. Backups obviously don't help you retrieve stolen data."

Go deeper: Choice to pay ransomware might be simpler than you'd think

Go deeper

The rise and rise of ransomware

Illustration: Aïda Amer/Axios

Ransomware attacks are becoming smarter, more common, and more dangerous.

What's happening: In ransomware incidents, attackers take systems down and demand payment (usually in bitcoin) to restore access to them.

Cities and counties take charge to combat coronavirus

Illustration: Sarah Grillo/Axios

Local leaders have seized the reins during the novel coronavirus outbreak, amid frustrations that the federal government's efforts have fallen short.

The big picture: Governors and mayors have been the ones dictating the pace of the response — closing schools, banning large gatherings and updating their residents. But cities also say they need more money from the federal government, and more help understanding how they're allowed to use the money they have.

Go deeperArrowMar 18, 2020 - Health

U.S. coronavirus cases top 1,000 as states scramble to curb the spread

A stretcher is moved from an AMR ambulance to the Life Care Center of Kirkland in Washington state. Photo: Jason Redmond/AFP via Getty Images

The number of cases of the novel coronavirus in the U.S. soared to 1,037 and the death toll to at least 31 by early Wednesday, per data from Johns Hopkins and state health departments.

The big picture: Nearly 40 states had reported cases by Tuesday and at least 12 have declared a state of emergency — Washington, California, New York, Oregon, Kentucky, Maryland, Utah, Colorado, North Carolina, Massachusetts, Florida and Michigan — which reported its first two cases on Tuesday evening.

Go deeperArrowUpdated Mar 11, 2020 - Health