In 2018, the city of Atlanta was targeted in a ransomware attack. It was the largest successful breach of security for a major American city by ransomware. Most of the city’s computers remained off for a week and it was estimated a third of the software used by the city was still down three months later. Ultimately, the city needed some $10 million in contractor work to recover the files that had been disabled by Iranian-based hackers.
Earlier this year, Fulton County was hit by another attach by the Russian-based LockBit hacking operation. This attack was mostly focused on the court system but also included the county’s water billing system. Some parts of the court system, such as Probate, were down for weeks. LockBit is one of several cyber groups operating around the world, launching hundreds of attacks per month. Boeing, the Industrial and Commercial Bank of China, and the UK Royal Mail postal service have all been victims of LockBit (just this month, the U.S., U.K. and Australia jointly named a Russian national Dmitry Khoroshev as the operator of LockBit). Estimates are that LockBit extorted some $500 million from its victims.
On Thursday, the Atlanta Regional Commission (ARC) held a joint exercise that included some 150 people from the City of Atlanta and Clayton, Cobb, DeKalb, Fulton, and Gwinnett counties. The move represents the first time multiple jurisdictions in metro Atlanta have come together for a cyberterrorism exercise. This is slightly different from a ransomware attack like Atlanta and Fulton County faced but those attacks certainly drove home the awareness of the issue and possible vulnerability. The scenario during the training on Thursday involved an effort to derail a train, interfere with voting systems and using artificial intelligence to drive disinformation.
“When it comes to a cyberattack involving our local governments, it’s a matter when, not if,” said Bernard Coxton, Director of Homeland Security & Emergency Preparedness at ARC. “Our goal with this training exercise is to enhance our collective ability to prevent, detect, respond to, and recover from a cyber incident.”
A range of officials from the involved communities included IT professionals, and representatives from legal, law enforcement, fire, finance, communications and elections departments. Coordinated by ARC’s Homeland Security and Emergency Preparedness Department, the training looks to identify gaps in response and coordination that could hamper efforts to combat the attack.
“Cyberterrorism must be addressed from a regional level,” said Anna Roach, ARC Executive Director & CEO. “We know from experience that an attack on one jurisdiction can spread to others in the area, so it’s imperative that our local governments are able to work together and respond in real time to mitigate any damage.”



