lockbit3 attacks town of stmarys
St. Marys, Ontario, Suffers Ransomware Attack by LockBit 3.0
Impact and Response
The small town of St. Marys, Ontario, became a target of the infamous LockBit 3.0 ransomware group, leading to a significant cybersecurity breach that incurred over $1.3 million in management costs. This incident, which took place on July 20, 2022, was identified amidst a routine system backup by the town's IT personnel.
In response to the attack, which encrypted files and servers, the town acted swiftly to mitigate further damage. Key municipal services, including transit and water systems, remained operational, preserving approximately 80% of town functionality. To navigate through the incident, St. Marys enlisted Deloitte for technical leadership and forensic auditing, alongside Siskinds LLP for incident response direction.
Cost and Recovery
The financial toll of the incident encompassed $860,970 allocated for incident management and investigation, alongside a ransom payment close to $300,000 in Bitcoin to secure decryption keys. Additionally, $440,133 was directed towards reconstructing the town's IT network, a project completed by Deloitte and subsequently transitioned to the town in November 2022.
Vulnerabilities and Prevention
The LockBit 3.0 attack underscores the critical need for stringent cybersecurity defenses, especially within the government sector. Despite St. Marys' initiative to migrate its operating environment to the cloud in 2020—a move that safeguarded critical services—the town still fell prey to the ransomware group. Cybersecurity specialists advocate for preemptive strategies, including regular security evaluations, employee training, and the engagement of third-party monitoring services to deter and diminish the impact of cyber threats.
The ransomware assault on St. Marys underscores the persistent menace posed by cybercriminals and the imperative of comprehensive cybersecurity protocols. Despite the substantial financial and operational upheaval inflicted by the attack, the town managed to recuperate and reinstate its systems, thanks to professional intervention.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!