Back in March the Cobb County government’s online systems were paralyzed by a cybersecurity attack that forced them to take multiple servers offline as they searched for the cause of the “unusual traffic” detected by the county’s IT department.

Fast forward to last week and the perpetrators behind that attack revealed themselves, demanding a ransom of at least $1 million lest they publish the 400,000 documents they stole onto the dark web – an unmonitored, anonymous version of the internet known for hosting illegal activities like drug sales, hacking tools and stolen data.  A sampling of 16 images sent to the county as evidence included autopsy photos, driver’s licenses, and social security cards. 

The group behind the hack is Russia-based Qilin, who claimed to have stolen some 150 gigabytes of sensitive data from Cobb County’s servers.  They gave the county until this past Saturday to pay the ransom, a sum that a county spokesman said it will not pay.

“A third party issued a ransom demand, which we declined. We refuse to support or enable criminal enterprises, even when faced with difficult choices. While we understand this may offer limited comfort to those affected, standing firm sends a clear message: bad actors will not profit from this crime.”

Information from government employees, county residents, and even county jail inmates is at risk.  Cobb residents are advised to monitor their accounts for any signs of suspicious activity, and to change passwords and implement two factor authentication if concerned.

The county spokesman couldn’t confirm if the data had actually been released onto the dark web at this time, but that it was investigating and urged Cobb residents to remain vigilant.

“If we determine that specific personal information is at risk, Cobb County will provide those individuals with credit monitoring and identity theft protection,” the spokesperson said. “We also urge all residents to remain vigilant. Monitor your financial accounts closely and immediately report any suspicious activity to your financial institution. Currently, there is no evidence that any individual has experienced harm due to this incident.”

 

Login

Lost your password?