When Ransomware Cripples a City, Who’s to Blame? This I.T. Chief Is Fighting Back

Lake City, Local Government, Hacker (Computer Security), Extortion And Blackmail, Computer Security, Cyberwarfare

The former information technology director of a northern Florida city forced to pay $460,000 after a ransomware attack was fired. Now he’s suing.

Lake City, Local Government


Cities across the U.S. are grappling with ransomware attacks that can cost millions. A new lawsuit raises the inevitable question: When hackers wipe out a city’s computer system, who is to blame?

The former information technology director of a northern Florida city forced to pay $460,000 after a ransomware attack was fired. Now he’s suing.

Brian A. Hawkins Googles his name and last employer and winces. The words that appear are verbs like “fired,” “axed” and “sacked.” The former information technology director of Lake City, the northern Florida city that was forced to pay out nearly half a million dollars after a ransomware attack this summer, was blamed for the breach, and for the long time it took to recover. But in a new lawsuit, Mr. Hawkins said he had warned the city about its vulnerability long ago — urging the purchase of an expensive, cloud-based backup system that might have averted the need to pay a ransom. But there was no money. And to those weighing the many competing priorities in the northern Florida city of 12,000 people, purchasing capacity on remote computer servers didn’t seem to rise to the top — at the time. Once the city’s entire computer network crumbled in the space of a few hours, there was an intense round of finger-pointing, and it ended with Mr. Hawkins. “My name has been blasted all over the media and across the country for weeks,” he said in his first interview with the news media since the attack earlier this summer. The recent cyberattack in Texas , which crippled the computer systems of nearly two dozen cities simultaneously, has served as another reminder of how outgunned most municipalities are against sophisticated hackers. With cities from Florida to Maryland grappling with an onslaught of ransomware attacks that are costing millions, the harsh reality is that it is often one- or two-person information technology offices with meager budgets and strict spending rules that are the main lines of defense. [Ransomware attacks are testing resolve of cities across America] They are often up against organized criminals and nation-state actors who know how to take advantage of their weaknesses, and who are able to refine their weapons with the hundreds of thousands of dollars in ransoms being paid by vulnerable cities. The lawsuit Mr. Hawkins filed in Columbia County state court on Aug. 9 raises the inevitable question of liability: When hackers wipe out a city’s computer system, who is to blame? “There is a push for accountability, which means firing people. It almost never happens,” said James A. Lewis, a researcher at the Center for Strategic and International Studies. “A lot of times ransomware exploits a vulnerability that should have been fixed. You need to look: Did somebody slip up on the job?” Two high level I.T. employees were fired after an attack this year in Baltimore, but city officials denied that the dismissals were related, The Baltimore Sun reported. No one in the Texas city of Laredo was disciplined after an attack there. A spokesman for the Texas Department of Information Resources declined to comment, citing the pending investigation. The troubles in Lake City, about an hour west of Jacksonville, began when several city employees reported that they had fallen for a phishing attack. Employees at the city clerk’s office, water plant and airport had clicked on an email purportedly from one of their contacts that said something like, “you have an invoice ready.” It was personalized and looked legitimate, but it was really a spear phishing attack, using what is known as Ryuk “triple threat” ransomware. One of the emails was cleverly disguised: It even made reference to a prior conversation the city employee had had via email, Mr. Hawkins recalled. The email had bypassed spam filters and antivirus software, which Mr. Hawkins said were both up-to-date. “They were super crafty,” Mr. Hawkins said. Mr. Hawkins took the city’s network offline, re-imaged the computers and took other normal precautions. But deep down, he knew that trouble could be looming if anyone else had clicked on the suspicious email without reporting it. The next sign of trouble emerged a few weeks later, on a weekend in early June, when the email system began running slowly. Nobody works on the weekends at City Hall. So Mr. Hawkins waited until Monday morning to tackle the problem, but by then, it was too late. All of the city’s files were encrypted, and a note had been left on the city’s servers that read: “How do you want to open this type of file? Balance of shadow universe.” Phones were down, email was out of commission, computers did not work and even the photocopiers were inoperable. The hackers who had left the note subsequently asked for exorbitant sums of money to release the city’s data. Even after the city’s insurer paid 42 bitcoin — about $460,000 — for the key to decrypt the files, it took weeks for the city to recover. Some files appear to be still missing, and presumably are lost, said Joseph Helfenberger, the city manager. Mr. Hawkins got a formal letter from Mr. Helfenberger on June 21. “Recent events, including a cyberattack on the City of Lake City and the inability to quickly recover from this attack, including the failure to have in place a reliable and effective backup system,” it said, “have demonstrated significant weaknesses with the city’s I.T. department under your leadership.” Mr. Hawkins was fired. Mr. Hawkins said that the city could have been able to recover quickly from the attack had it agreed to purchase the off-site, cloud-based backups he had recommended in 2017. City officials balked at the price, and went for backups located on the same server, which the hackers sabotaged, he said. The city did pay for a cloud-based backup for the applications used to run day-to-day business, which was why the city was able to continue offering services. “It was pretty tough, especially after working so hard toward recovery,” Mr. Hawkins said. “Yes, we were affected, yes, we were crippled, but we were still serving the citizens of Lake City the very next day.” Mr. Hawkins filed a public records request for his own hard drive and emails that would prove that he had suggested the extended cloud purchase. His lawsuit this month seeks a court order to disclose the material. After the lawsuit was filed, the city responded, but said it would be charging about $7,000 to review and redact the records, said Adam Morrison, Mr. Hawkins’s lawyer, who said he was also considering filing a defamation lawsuit. Mr. Helfenberger, the city manager, said that because of the lawsuit he was limited in how much he could say on the matter. “Brian Hawkins might have talked to somebody in 2017 about the need for some improvements, but I did not start working here until August 2018,” Mr. Helfenberger said. “I don’t know if he would have put in all the measures we are putting in right now. There are other issues besides this. This was not the only reason he was terminated.” Mr. Hawkins got another job at WatchPoint Data , a firm that has created a tool that helps fight ransomware attacks. “As soon as I saw the stories breaking that he had been fired, I immediately thought: scapegoat,” said Greg D. Edwards, WatchPoint’s chief executive. “He was doing the things he knew to do.” Roy E. Hadley, Jr., a lawyer who leads the municipal cyber practice for a Georgia firm that represents the city of Atlanta, which was hit by ransomware last year, said incidents like the one in Lake City underscored what cities may come up against: sophisticated hackers, some of whom may have foreign government backing, whose only job is to launch cyber attacks. While no government has been accused in any of the most recent round of municipal cyber attacks, federal authorities identified the digital fingerprints of the Russian military intelligence agency in an intrusion of Read more: The New York Times

How many hackers to you need to euthanize before its no longer a problem? I thought the usairforce was on this whole cyber crimes thing. Sounds like a symptom of thectimes we live in Whole nations having their infrastructure systematically destroyed by the elites programme what else can u expect for creative minds

'When someone does something bad who did the bad thing!?' Thats what you sound like. That's you right now. 'When a crime is committed, is the criminal responsible?' What idiocy. It's almost like, 'well if you don't want your system kidnapped and held for ransom, it shouldn't have left the house in that skirt.' Duh.

L.A. is dealing with the greatest homeless crisis, medieval disease, poverty, and one of the worst public school systems in the nation. All at the hands of MayorOfLA and the LACityCouncil All Democrats. Possible bigger question why did they have a separate backup system. Money is a cheap excuse,have to do better.

The 'hackers'. Does anyone else read these titles in mikiebarb voice? No? Just me?! “I’m Michael Barbaro, see you tomorrow!” “Here’s... what else... you need... to know today.” I’m sorry I’m a Northern Englander and I love his voice. 👀🏴󠁧󠁢󠁥󠁮󠁧󠁿🇬🇧🇺🇸 Got our school 2 weeks ago (Stevens Tech), I still don’t have access to my computer!

Amazon Rainforest Fires: Here’s What’s Really HappeningHere's what we know so far about the fires raging in the Amazon: – Brazil’s space research center said it detected thousands of fire – A majority of the fires were set by farmers – The blazes could jeopardize the Earth’s “lungs' See more: jairbolsonaro só está cumprindo à risca suas promessas de campanha I think the headline here should be “Brazil actually has a space research center!”

For some, currency wars may not be fun or easy to winIt's a maxim for private investors: Don't fight the Fed. 550pts is not what it used to be. Cuban missile crisis cost the dow 3.5% and even then didn’t connote much fear in the consumer Interesting choice of photo Sometimes my feelings on Forex

Ransomware Attacks Are Testing Resolve of Cities Across America22 cities across Texas are simultaneously being held hostage for millions of dollars after a sophisticated hacker, perhaps a group of them, infiltrated their computer systems and encrypted their data I read that access was gained through data sharing links between municipalities. (Law enforcement agencies) America is not investing in cyber security. Very simple APompliano The hackers demand Bitcoin! 🤷‍♂️

Skinny Jeans Are Back: 24 Ways to Wear the Style This FallOne of your favorite denim classics is back for Fall, and it's more versatile than ever before. After years of opting for more wide-leg, tailored, or straight

Cyberattacks on Texas cities put other governments on guardCHICAGO (AP) — Cyberattacks that recently crippled nearly two dozen Texas cities have put other local government s on guard, offering the latest evidence that hackers can halt routine operations by... i hope the hackets dont steal my porn As they should. Ever work in a government office? Feels like a senior's course on computer literacy half the time. Everything in Texas is bigger, including cyber attacks.

Meet The Next 'Generation' In 'The L Word' Reboot TrailerNow in much better news: The trailer for the reboot of 'The L Word'

NY governor says China is donating 1,000 ventilators to the state

Billionaire Brooklyn Nets owner Joe Tsai donates ventilators and masks to New York

Coronavirus live updates: Global deaths pass 60,000 - CNN

Man’s Anxiety Not About To Let Depression Muscle In On Turf

Self-Isolated Woman Going So Crazy She’s Started Talking To Her Spouse

Biden says he informed Sanders he will begin the VP vetting process

Kushner 'has no idea what he's doing' political reporter states

Write Comment

Thank you for your comment.
Please try again later.

Latest News


23 August 2019, Friday News

Previous news

Trump fires back at China, announces tariffs to increase amid escalating trade war

Next news

Trump Says He’ll Raise Existing Tariffs To 30%, Escalating Trade War With China
A Florida fire crew used a ladder to surprise a firefighter with coronavirus at his hospital window Woman Has Few Enough Friends To Consider Confiding In Sister NY blood center calls for plasma donations from recovered COVID-19 patients Intelligence expert on Atkinson firing: 'Trump's middle name is retribution' Coral Princess docks in Miami with 2 dead and several ill of coronavirus, after ports shunned it for days Six-year-old 'cystic fibrosis warrior' celebrates recovering from COVID-19 New York City schools won't be using Zoom anymore because of security concerns New York gets Chinese ventilators; Trump wants more thanks\n NYC sees largest spike in deaths since outbreak started Opinion | How Democrats can channel FDR to save America (again) Undocumented house cleaner in Seattle: ‘I have no money at all if I get sick’ Trump Backs Dismissal of USS Roosevelt Captain
NY governor says China is donating 1,000 ventilators to the state Billionaire Brooklyn Nets owner Joe Tsai donates ventilators and masks to New York Coronavirus live updates: Global deaths pass 60,000 - CNN Man’s Anxiety Not About To Let Depression Muscle In On Turf Self-Isolated Woman Going So Crazy She’s Started Talking To Her Spouse Biden says he informed Sanders he will begin the VP vetting process Kushner 'has no idea what he's doing' political reporter states Tennessee 6-year-old with cystic fibrosis beats coronavirus: ‘Thank you God,’ mom says A gender reveal party ignited a 10-acre brush fire in Florida, fire officials say Kobe Bryant headlines Hall of Fame class How to make your own face mask Trump considering second task force on reopening economy