lockbit3 attacks town of stmarys

Incident Date: Jul 22, 2022

Attack Overview
VICTIM
town of stmarys
INDUSTRY
Government
LOCATION
Canada
ATTACKER
Lockbit
FIRST REPORTED
July 22, 2022

St. Marys, Ontario, Suffers Ransomware Attack by LockBit 3.0

Impact and Response

The small town of St. Marys, Ontario, became a target of the infamous LockBit 3.0 ransomware group, leading to a significant cybersecurity breach that incurred over $1.3 million in management costs. This incident, which took place on July 20, 2022, was identified amidst a routine system backup by the town's IT personnel.

In response to the attack, which encrypted files and servers, the town acted swiftly to mitigate further damage. Key municipal services, including transit and water systems, remained operational, preserving approximately 80% of town functionality. To navigate through the incident, St. Marys enlisted Deloitte for technical leadership and forensic auditing, alongside Siskinds LLP for incident response direction.

Cost and Recovery

The financial toll of the incident encompassed $860,970 allocated for incident management and investigation, alongside a ransom payment close to $300,000 in Bitcoin to secure decryption keys. Additionally, $440,133 was directed towards reconstructing the town's IT network, a project completed by Deloitte and subsequently transitioned to the town in November 2022.

Vulnerabilities and Prevention

The LockBit 3.0 attack underscores the critical need for stringent cybersecurity defenses, especially within the government sector. Despite St. Marys' initiative to migrate its operating environment to the cloud in 2020—a move that safeguarded critical services—the town still fell prey to the ransomware group. Cybersecurity specialists advocate for preemptive strategies, including regular security evaluations, employee training, and the engagement of third-party monitoring services to deter and diminish the impact of cyber threats.

The ransomware assault on St. Marys underscores the persistent menace posed by cybercriminals and the imperative of comprehensive cybersecurity protocols. Despite the substantial financial and operational upheaval inflicted by the attack, the town managed to recuperate and reinstate its systems, thanks to professional intervention.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.