Vicksburg, Mississippi, experienced a ransomware incident that caused the city’s computer systems to be shut down temporarily on Oct 1.
Mayor Willis Thompson stated that utility services, 911, and the Police and Fire Departments were not impacted and remained operational. However, individuals attempting to make in-person payments for utilities may experience delays.
The city continues to work on restoring systems.
Michael Centrella, Head of Public Policy at SecurityScorecard, comments, “Protecting emergency services is only one part of a city’s ransomware response. Vicksburg says 911, police, fire and utility services remain operational, but the shutdown of city computer systems may delay in-person utility payments. The city has said it will suspend late-payment penalties and service shutoffs while systems are offline, helping protect residents from consequences caused by the outage.
“The next question is what it will take to restore those systems safely. Investigators need to establish how the attackers gained access, which systems and accounts they reached, and whether any access remains. Bringing a payment system back online before those questions are answered could leave the city vulnerable to renewed disruption. Local governments also need to test whether essential functions can continue when the systems they normally depend on have to be disconnected.
“The potential data exposure creates a separate concern. Vicksburg is still determining whether information relating to customers, employees, contractors or business partners was accessed or stolen. Restoring services will not resolve that question. If information was taken, the consequences could continue after the visible disruption ends. If data exposure is confirmed, the city should clearly communicate what information was involved and who was affected so those individuals can understand their own risk.”
At this time, external cybersecurity experts are conducting an investigation.
“One of the top priorities of our investigation is determining whether there was any compromise of personal or confidential information relating to current and/or former customers, contractors, vendors, employees, or affiliated business partners of the city,” says Thompson. “At this time, the investigation is ongoing, and the city has not reached a final determination regarding what information, if any, may have been accessed or acquired without authorization.”
Click Here For The Original Source.
