Cyber Crime

City of Knoxville shuts down IT network after ransomware attack

A ransomware attack that targeted the offices of the City of Knoxville, Tennessee, forced to shut down its entire computer network.

The city of Knoxville, Tennessee, has shut down its computer network following a ransomware attack.

The attack took place in the night between June 10 and June 11, the malware encrypted multiple systems in the IT network.

According to Chief Operations Officer David Brace, the attack has been discovered by employees of the city’s fire department around 4:30 AM, June 11. Brace said The Tennessee Bureau of Investigation and the Federal Bureau of Investigating is investigating into the incident.

Knoxville is the third-largest city in Tennessee, after Nashville and Memphis, and has a population of over 180,000.

“The City of Knoxville computer networks have been attacked by ransomware, according to an email sent to city employees.” reported WVLT.

“Please be advised that our network has been attacked with ransomware,” said the notice sent Thursday morning. “Information Systems is currently following recommended protocols. This includes shutting down servers, our internet connections, and PCs. Please do not log in to the network or use computer applications at this time.”

At this time, the website of the City of Knoxville is still down and the City Court sessions have also been canceled. The city’s Fire Department spokesmen D.J. Corcoran and Scott Erland said that both Fire Department and Police Department operations are not affected following the security breach, but employees cannot access the city’s network.

A city spokesperson confirmed that City offices and services are open, though citizens may encounter some inconveniences.

COO David Brace pointed out that no personal information was accessed during the attack. The City will use backup to resume operations, the good news is that backup servers were not affected.

“No credit card information is stored by the City, so individuals who have made any online reservations of City facilities are not believed to be at risk,” Knoxville spokesman Eric Vreeland told WBIR.

Operators behind the attack have already asked the payment of a ransom, but the City’s administration will not pay it.

“Brace said the attackers have requested a ransom payment to free city files they control, but he declined to reveal the amount or speak about the process other than to say forensic analysists and risk management consultants are working with law enforcement to resolve the issue.” reported Knox News.

“Ransomware is we lock your stuff down and (you) give us money to get your stuff back,” he said. “It’s not good. That’s exactly what has happened, and our experts are working on that and how to tackle it.”

It is still unclear which is the malware family that infected the systems of the City.

Small cities are a privileged target for ransomware operators, it is quite easy for them to infect their systems.

Other US cities that suffered similar incidents are AtlantaDenverNew Orleans, Baltimore, Ocala, Naples, Lake City, Riviera Beach City, Pensacola City, Jackson County, Racine, and Palm Beach.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Knoxville, ransomware)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Cryptocurrencies and cybercrime: A critical intermingling

As cryptocurrencies have grown in popularity, there has also been growing concern about cybercrime involvement…

28 mins ago

Kaiser Permanente data breach may have impacted 13.4 million patients

Healthcare service provider Kaiser Permanente disclosed a security breach that may impact 13.4 million individuals…

49 mins ago

Over 1,400 CrushFTP internet-facing servers vulnerable to CVE-2024-4040 bug

Over 1,400 CrushFTP internet-facing servers are vulnerable to attacks exploiting recently disclosed CVE-2024-4040 vulnerability. Over…

3 hours ago

Sweden’s liquor supply severely impacted by ransomware attack on logistics company

A ransomware attack on a Swedish logistics company Skanlog severely impacted the country's liquor supply. …

5 hours ago

CISA adds Cisco ASA and FTD and CrushFTP VFS flaws to its Known Exploited Vulnerabilities catalog

CISA adds Cisco ASA and FTD and CrushFTP VFS vulnerabilities to its Known Exploited Vulnerabilities…

16 hours ago

CISA adds Microsoft Windows Print Spooler flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA added the Windows Print Spooler flaw CVE-2022-38028 to its Known Exploited Vulnerabilities catalog.…

23 hours ago

This website uses cookies.