Cities Held Hostage — A Brave New World

Jul 11, 2019 | Cyber Security, IT News

In the course of a single week, three cities in Florida were struck with three separate ransomware attacks. At the time of writing this, two of the three gave in to the ransom demands and the third is still considering it. Almost immediately following these incidents in Florida, Georgia’s state court system was also hit. This was the second time this year for Georgia, following an event which completely crippled Atlanta’s IT network. Officials paid off the attackers with a hefty $400,000 ransom payment, and it is currently unknown if Georgia will be paying the ransom again this time.

Each of these attacks and capitulations have occurred within a worrisome and remarkably short period of time. It’s also worth noting that all of these events take place merely weeks after the announcement of a ransomware attack on Baltimore — an attack that cost the city $18.2 million to recover from. Here is a breakdown of each one as they happened.

Ransomware Attack on Riviera Beach, Florida

The Riviera Beach attack began on May 29, 2019, after a police department employee opened an infected email attachment. All the city’s online systems — including email, phones, as well as water utility pump stations — were brought completely down. Utility payments could not be accepted other than in person or by regular mail, and only by check or cash. On June 4, 2019, the city authorized spending more than $900,000 to buy new computer hardware. Notice of the attack was officially made public on June 5. The city agreed to pay nearly $600,000 to the hackers who paralyzed its computer systems, and at the time of writing, there are no guarantees that Riviera Beach’s records will be returned once the ransom is paid.

Ransomware Attack on Lake City, Florida

In the same week as Riviera Beach, Lake City suffered a catastrophic malware infection which the city described as a “triple threat” — an attack that is made up of three separate parts. Once again, it was caused by a single employee opening a document attached to an email. The document contained the TrickBot trojan, which later downloaded the Emotet trojan, and later, the Ryuk ransomware — thus completing the triple-threat design. Despite the city’s IT staff disconnecting impacted systems within 10 minutes of detecting the attack, the ransomware infected almost all its computer systems with the exception of the police and fire departments, which ran on a separate network. Lake City government was entirely crippled for two weeks. A ransom demand was made a week after the infection, with hackers reaching out to the city’s insurance provider. The city’s insurance paid a portion of the nearly $500,000 ransom demand, with the remainder of it being shouldered by the taxpayers.

Ransomware Attack on Key Biscayne, Florida

This was another triple-threat attack that was yet again caused by someone clicking on a bad link. Key Biscayne has become another victim of the same Ryuk ransomware that infected Lake City. The “data security event” occurred on June 23, 2019,, and it is unknown at this time if city officials will be paying the ransom. Officials held a special council meeting to discuss the issue, where it was decided to spend $30,000 on hiring a data recovery firm, though it appears the city isn’t ruling out paying the hackers.

Cities Held Hostage — A Brave New WorldIf you’re noticing a pattern to these events, you’re certainly not alone. In each case, it was due to a city employee opening an email and then clicking on a link or attached document. It’s now been confirmed, in fact, that the employee responsible for having allowed the Lake City attack to occur has been officially let go. These are prime examples of how all it takes is just one simple mistake from a single employee for everything to come crashing down. Is your business prepared for this “brave new world” we’re all living in?

 

Since 1995, Manassas Park, VA-based V2 Systems has employed local systems administrators, network engineers, security consultants, help desk technicians and partnering companies to meet a wide range of clients’ IT needs, from research, to implementation, to maintenance. Concentrate on your VISION…We’ll handle the TECHNOLOGY!

 

More From V2 Systems

Summer Cyber Risks: Why Attacks Spike When Teams Are Short-Staffed

Summer vacations, lighter staffing, remote work, and busy schedules can create cybersecurity gaps for small businesses and government contractors. This blog explains why attackers take advantage of short-staffed teams and what organizations can do to reduce risk during the summer months.

Why Security Awareness Training Fails and How to Fix It

Security awareness training often fails because it is too generic, too infrequent, or too disconnected from how employees actually work. This blog explains why annual training alone is not enough and how small businesses and government contractors can build a more practical, ongoing approach to cybersecurity awareness.

Cybersecurity Fatigue Is Real: How to Keep Employees Engaged Without Burnout

Employees play a critical role in cybersecurity, but constant warnings, training reminders, password prompts, and security alerts can lead to fatigue. This blog explains how small businesses and government contractors can keep employees engaged with cybersecurity without overwhelming them.

How Government Contractors Can Stay Secure During Disruptions and Staffing Gaps

Disruptions are unavoidable, but security gaps do not have to be. For government contractors, staffing shortages, PTO, turnover, shutdowns, and contract transitions can create real cybersecurity and compliance risk. This blog explains how GovCons can maintain security, protect sensitive data, and keep operations moving when key people are unavailable.

Backups Alone Are Not Enough: What True Recovery Looks Like in 2026

Backups are a critical part of business resilience, but they are not the same as recovery. In 2026, small businesses and government contractors need validated backups, tested recovery procedures, clear response plans, and secure restoration processes to keep operations moving when ransomware, outages, or system failures occur.

Free
Small Business Cybersecurity Checklist

cybersecurity checklist graphic