Full Report
The City of Norcross is notifying residents that it recently identified a ransomware incident that occurred on August 1, 2026, and which impacted certain computer systems. As soon as the incident was detected, the City took immediate steps to respond, including engaging experienced cybersecurity professionals and notifying law enforcement. We continue to actively work with these partners to investigate the incident and to help ensure the continued security of our systems. Most City systems and services are currently operational. However, residents may continue to experience limited disruptions to certain services as the City completes its restoration efforts and implements additional security measures. The City is working to safely restore all remaining affected systems as quickly as possible while maintaining the security and integrity of its network. Because the investigation is ongoing, the City is not able to share additional details at this time. As we are able, we will provide more information as the investigation continues and as it becomes available.
Analysis Summary
# Incident Report: City of Norcross Ransomware Attack
## Executive Summary
The City of Norcross, Georgia, experienced a ransomware incident on August 1, 2026, which impacted several municipal computer systems. The City initiated immediate response protocols, including the engagement of third-party cybersecurity experts and law enforcement, to contain the threat and restore operations. While most services have returned to operational status, the City continues to work on full system restoration and hardening.
## Incident Details
- **Discovery Date:** August 2026 (exact date not disclosed)
- **Incident Date:** August 1, 2026
- **Affected Organization:** City of Norcross
- **Sector:** Public Sector / Government
- **Geography:** Norcross, Georgia, USA
## Timeline of Events
### Initial Access
- **Date/Time:** August 1, 2026
- **Vector:** Unknown (Investigation ongoing)
- **Details:** Attackers successfully deployed ransomware affecting "certain computer systems."
### Lateral Movement
- **Details:** Specific lateral movement techniques have not been disclosed by the City at this time due to the ongoing investigation.
### Data Exfiltration/Impact
- **Details:** The primary impact was the encryption of municipal systems, leading to service disruptions for residents. The extent of data exfiltration is currently unknown.
### Detection & Response
- **Discovery:** Detected shortly after the August 1 event.
- **Response actions taken:**
- Engagement of cybersecurity professionals.
- Notification of law enforcement.
- Systematic restoration of systems from backups/integrity checks.
- Implementation of additional security measures.
## Attack Methodology
*Note: Due to the ongoing nature of the investigation and the limited public disclosure, specific MITRE ATT&CK mappings are currently restricted to the "Impact" phase.*
- **Initial Access:** Unknown.
- **Persistence:** Not disclosed.
- **Privilege Escalation:** Not disclosed.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Not disclosed.
- **Discovery:** Not disclosed.
- **Lateral Movement:** Not disclosed.
- **Collection:** Not disclosed.
- **Exfiltration:** Not disclosed.
- **Impact:** Ransomware (Data Encrypted for Impact).
## Impact Assessment
- **Financial:** Unknown; potential costs related to forensic investigation and system restoration.
- **Data Breach:** Under investigation; volume and type of data compromised are not yet confirmed.
- **Operational:** Limited disruptions to City services; ongoing restoration efforts for remaining affected systems.
- **Reputational:** Public notification issued to residents; potential loss of trust in municipal data handling.
## Indicators of Compromise
- **Network indicators:** None disclosed.
- **File indicators:** None disclosed.
- **Behavioral indicators:** Unauthorized encryption of system files; disruption of standard municipal IT services.
## Response Actions
- **Containment measures:** Isolation of affected computer systems upon detection.
- **Eradication steps:** Deployment of cybersecurity professionals to purge malicious actors and code from the network.
- **Recovery actions:** Progressive restoration of City systems and services; implementation of enhanced security controls.
## Lessons Learned
- **Key takeaways:** Rapid engagement of law enforcement and external experts is critical for municipal incident response.
- **What could have been done better:** Information is limited, but the delay between the incident (Aug 1) and the public notification (Aug 28) suggests a complex recovery or a need for a more streamlined communication plan.
## Recommendations
- **Prevention:** Implement Multi-Factor Authentication (MFA) across all municipal accounts.
- **Prevention:** Conduct regular, offline backups of critical data to ensure recovery without paying ransoms.
- **Prevention:** Perform routine vulnerability assessments and patch management on public-facing infrastructure.
- **Preparedness:** Update the Incident Response Plan to include specific communication templates for residents to reduce notification lag.