Cities Held Hostage — A Brave New World

Jul 11, 2019 | Cyber Security, IT News

In the course of a single week, three cities in Florida were struck with three separate ransomware attacks. At the time of writing this, two of the three gave in to the ransom demands and the third is still considering it. Almost immediately following these incidents in Florida, Georgia’s state court system was also hit. This was the second time this year for Georgia, following an event which completely crippled Atlanta’s IT network. Officials paid off the attackers with a hefty $400,000 ransom payment, and it is currently unknown if Georgia will be paying the ransom again this time.

Each of these attacks and capitulations have occurred within a worrisome and remarkably short period of time. It’s also worth noting that all of these events take place merely weeks after the announcement of a ransomware attack on Baltimore — an attack that cost the city $18.2 million to recover from. Here is a breakdown of each one as they happened.

Ransomware Attack on Riviera Beach, Florida

The Riviera Beach attack began on May 29, 2019, after a police department employee opened an infected email attachment. All the city’s online systems — including email, phones, as well as water utility pump stations — were brought completely down. Utility payments could not be accepted other than in person or by regular mail, and only by check or cash. On June 4, 2019, the city authorized spending more than $900,000 to buy new computer hardware. Notice of the attack was officially made public on June 5. The city agreed to pay nearly $600,000 to the hackers who paralyzed its computer systems, and at the time of writing, there are no guarantees that Riviera Beach’s records will be returned once the ransom is paid.

Ransomware Attack on Lake City, Florida

In the same week as Riviera Beach, Lake City suffered a catastrophic malware infection which the city described as a “triple threat” — an attack that is made up of three separate parts. Once again, it was caused by a single employee opening a document attached to an email. The document contained the TrickBot trojan, which later downloaded the Emotet trojan, and later, the Ryuk ransomware — thus completing the triple-threat design. Despite the city’s IT staff disconnecting impacted systems within 10 minutes of detecting the attack, the ransomware infected almost all its computer systems with the exception of the police and fire departments, which ran on a separate network. Lake City government was entirely crippled for two weeks. A ransom demand was made a week after the infection, with hackers reaching out to the city’s insurance provider. The city’s insurance paid a portion of the nearly $500,000 ransom demand, with the remainder of it being shouldered by the taxpayers.

Ransomware Attack on Key Biscayne, Florida

This was another triple-threat attack that was yet again caused by someone clicking on a bad link. Key Biscayne has become another victim of the same Ryuk ransomware that infected Lake City. The “data security event” occurred on June 23, 2019,, and it is unknown at this time if city officials will be paying the ransom. Officials held a special council meeting to discuss the issue, where it was decided to spend $30,000 on hiring a data recovery firm, though it appears the city isn’t ruling out paying the hackers.

Cities Held Hostage — A Brave New WorldIf you’re noticing a pattern to these events, you’re certainly not alone. In each case, it was due to a city employee opening an email and then clicking on a link or attached document. It’s now been confirmed, in fact, that the employee responsible for having allowed the Lake City attack to occur has been officially let go. These are prime examples of how all it takes is just one simple mistake from a single employee for everything to come crashing down. Is your business prepared for this “brave new world” we’re all living in?

 

Since 1995, Manassas Park, VA-based V2 Systems has employed local systems administrators, network engineers, security consultants, help desk technicians and partnering companies to meet a wide range of clients’ IT needs, from research, to implementation, to maintenance. Concentrate on your VISION…We’ll handle the TECHNOLOGY!

 

More From V2 Systems

What Government Contractors Get Wrong About Secure Cloud Environments

Secure cloud environments require more than moving files into Microsoft 365, SharePoint, or another cloud platform. For government contractors, controlled access, proper configuration, CUI scoping, enclaves, and shared system responsibilities all matter. This blog explains what GovCons often get wrong about cloud security and how to stay aligned with current CMMC expectations.

Hybrid Work in 2026: The Endpoint Problem That Never Went Away

Hybrid work is now a normal part of business, but the endpoint problem never went away. Laptops, mobile devices, remote access tools, and unmanaged personal devices can create cybersecurity risk when they are not properly secured. This blog explains how small businesses and government contractors can strengthen endpoint security in 2026.

CMMC Update: What Government Contractors Need to Know as of August 2026

The Department of War announced the immediate suspension of CMMC Phase II requirements on July 13, 2026, pausing upcoming third-party assessment mandates. However, Phase I self-assessments, NIST SP 800-171 Rev. 2, DFARS 252.204-7012, and core cybersecurity obligations remain active. This blog explains what government contractors need to know as of August 2026 and how to stay prepared during the review period.

Summer Cyber Risks: Why Attacks Spike When Teams Are Short-Staffed

Summer vacations, lighter staffing, remote work, and busy schedules can create cybersecurity gaps for small businesses and government contractors. This blog explains why attackers take advantage of short-staffed teams and what organizations can do to reduce risk during the summer months.

Why Security Awareness Training Fails and How to Fix It

Security awareness training often fails because it is too generic, too infrequent, or too disconnected from how employees actually work. This blog explains why annual training alone is not enough and how small businesses and government contractors can build a more practical, ongoing approach to cybersecurity awareness.

Free
Small Business Cybersecurity Checklist

cybersecurity checklist graphic