Six months after ransomware attack, Atlanta still has no answers
In March, a ransomware attack severely hit Atlanta's municipal government systems, delaying budget confirmations, taking hundreds of software programs offline, and pushing recovery costs to nearly $3 million. Six months later, the city is still rebuilding critical applications, but the motive behind the attack and the full extent of the damage remain unclear. Experts note that attacks like those by the SamSam group often stem from random scanning, while tight government budgets create a dilemma for security investment.

Cyberattacks are both unapologetic and invasive. In Atlanta's case,the March ransomware attackcarried a hint of irony: file names on city computers were altered to include the words "weapologize" and "imsorry."
The aftermath of the attack was severe enough to delay the confirmation of the city's 2019 budget and require city council employees to use "a clunky personal laptop" to work.
City and local government budgets are tight due to pressure to allocate funds to more voter-friendly projects. Atlanta, like any other local government, sometimes has to choose between investing in new city computers or public schools.
The private sector does not directly feel this issue. Although "sometimes you think the greater good is helping constituents," Chris Duvall, senior director at security and risk management firm Chertoff Group, told CIO Dive, risk trade-offs still need to be made.
The Georgia capital's technology infrastructure was thrown into encryption chaos, and the entire incident may have stemmed from an "opportunistic target," Duvall said.
SamSam strikes again?
Experts believe the hacker groupSamSamis behind the Atlantaransomwareattack. Hacker groups like SamSam tend to operate in a commercialized structure, with each hacker at a different level.
According to Duvall, in the hierarchy, some hackers are responsible for scanning random IP ranges for potential vulnerabilities, or filtering discovered vulnerabilities to determine which are worth pursuing.
This process continues until the remaining vulnerabilities are passed to the "real team," who enter the system, "live off the land," exploit vulnerabilities, and conduct reconnaissance on affected systems, he said.
There is no way to know why Atlanta was targeted. However, it is entirely possible that the city was found vulnerable during a random scan, and then someone said "we have a live target here," Duvall said.
Random attacks are escalating, and the idea that a city becomes a victim of chance is a sobering reality.
SamSam did not only target Georgia early in the year.
Colorado suffered consecutive attacks in 2018. In February, computers owned by the Colorado Department of Transportation were locked by ransomware,according to local reports. The Colorado attack has caused about$1.5 million in recovery costs。
However, about a week later, ransomware struck again, and employees had towork on paperinstead of using computers. Similar to Atlanta, hackers demanded ransom payments in Bitcoin, using a new variant of the SamSam ransomware.
Employees at the Colorado Department of Transportation were asked to conduct business "the old-fashioned way," a spokesperson for the state's Office of Information Technology said.
What was lost
Imagine facing a catastrophic ransomware attack just one month into a new role. That is what Daphne Rackley, Atlanta's interim chief information officer, experienced.
According to Rackley, during apublic meetingwith city council members on June 6, about 35% of the city's 424 software programs were taken "offline or partially offline" by the attack.
Of those, 49 affected applications were considered "mission-critical," and the scope of the attack seemed to "expand daily," Rackley said at the time.
Initially, Atlanta's Department of Information Management (AIM) believed there were about 22 mission-critical applications, but later found more "because [there are] a lot of interdependencies," she said. The affected applications had a direct impact on police and court services.
Some applications that needed to be rebuilt had vendors that needed to be involved in the process, which required paying for their services. Other applications could be built internally by AIM.
Decades of digital records and data, including some police dashcam footage, were considered permanently lost. "The city government cannot make up for these losses," Pravin Kothari, CEO of CipherCloud, told CIO Dive.
On the day of the attack, departments reported disruptions, leaving Atlanta Mayor Keisha Lance Bottoms and Chief Operating Officer Richard Cox uncertain about the scope. At the very least, the government expected a major overhaul of its technology infrastructure, starting with restoring fully operational servers.
"Once the attack is launched, it will access and encrypt shared data," Brian Vecci, a technical evangelist at Varonis, told CIO Dive. Frequently accessed data is open and unmonitored.
Rising costs
The ransom demanded by hackers was Bitcoin valued at $6,800 per unit, equivalent to about $51,000. The city chose not to pay, but in the first month of recovery alone, Atlanta spent nearly $3 million, according to data from the city'sprocurement department.
When replacement, rebuilding, and third-party partnerships need to be considered, the cost of a cyberattack is ongoing. But disaster recovery often wreaks havoc on budgets. Recovery costs are rising, but "it takes time and a lot of money, most of which is unbudgeted," Kothari said.
At the June budget meeting, Rackley said her department needed an additional $9.5 million, but the department only received an increase of about $3.5 million in the passed budget.The passed FY19 budget was about $38 million for AIM, a 10% increase over the FY18 passed budget and the FY19 proposed budget,according to public records。
The final budget was approved on June 18, and mentioned upgrading Atlanta's IT security and infrastructure. Actual spending will be seen in the coming year.
Where Atlanta goes from here
Rackley said that due to constraints of time, money, and security quality, the city will have to rebuild applications "in our current hardened environment."
"Procuring equipment is a hurdle, and 'rip and replace' is another issue," Vecci said. Government agencies have to deal with such incidents by finding "contract vehicles they can execute such orders on."
As long as applications are not "homegrown," they are easier to rebuild, Duvall said. However, what really matters is the data behind the applications, which is why organizations need to be aware that attackers aretargeting backup keys。
"It's a bit like chess," Duvall said. Organizations want to back up regularly, but now backups are not enough. To avoid becoming an unwitting and random victim of ransomware, protective measures around backups are essential.