Full Report
The City of Stevens Point is working to get many of its city services running again after a cybersecurity incident. City staff believe they stopped the beginning of a ransomware attack last week. “Had they not caught the threat as early as they did, we could be in a much worse spot,” said Stevens Point Mayor Mike Wiza. City staff noticed an issue after learning their servers were online but failing to communicate. Workers shut down access to the servers and began investigating.
Analysis Summary
# Incident Report: Attempted Ransomware Attack on the City of Stevens Point
## Executive Summary
The City of Stevens Point, Wisconsin, successfully intercepted an attempted ransomware attack before malware encryption could be initiated or data could be stolen. IT staff detected the unauthorized network breach after noticing that city servers were online but failing to communicate normally, alongside anomalies across several endpoints. While emergency services remained fully functional, the city proactively isolated its network and quarantined approximately 240 devices, initiating a structured recovery process expected to last one to two weeks.
## Incident Details
- **Discovery Date:** Wednesday, September 23, 2026 (Estimated based on report publication)
- **Incident Date:** Week of September 21, 2026
- **Affected Organization:** City of Stevens Point
- **Sector:** Government / Municipal Services
- **Geography:** Stevens Point, Wisconsin, United States
## Timeline of Events
### Initial Access
- **Date/Time:** Undisclosed / Under investigation
- **Vector:** Undisclosed / Under investigation
- **Details:** Attackers gained unauthorized access to the city's network environment, preparing for a planned ransomware deployment.
### Lateral Movement
- **Details:** The threat actors moved laterally to multiple systems. Post-incident inspection revealed that several machines exhibited suspicious activity and configuration anomalies.
### Data Exfiltration/Impact
- **Details:** Based on the current forensic investigation, there is no evidence that any data was exfiltrated or stolen. The operational impact was limited to the proactive shutdown of city servers and temporary disruption of standard municipal digital services.
### Detection & Response
- **Details:** IT staff observed that servers were online but failing to communicate properly. Upon identifying these anomalies, workers immediately cut off access to the servers, quarantined affected devices, and established alternative internet access to begin a systematic investigation of all city endpoints.
## Attack Methodology
- **Initial Access:** Under investigation.
- **Persistence:** Undisclosed.
- **Privilege Escalation:** Undisclosed.
- **Defense Evasion:** Undisclosed.
- **Credential Access:** Undisclosed.
- **Discovery:** Undisclosed.
- **Lateral Movement:** Automated or manual propagation across multiple internal systems, resulting in anomalies on several machines.
- **Collection:** None identified.
- **Exfiltration:** None identified; no evidence of data theft.
- **Impact:** Resource Hijacking / Attempted Service Disruption. The attackers intended to launch a ransomware strain, but the execution phase was intercepted by the security team.
## Impact Assessment
- **Financial:** Undisclosed; remediation costs are currently bounded by internal IT labor and investigative efforts rather than extortion payments.
- **Data Breach:** None; no indicators of compromise suggest data theft occurred.
- **Operational:** Moderate. Non-emergency city services and internal server communications were taken offline. Approximately 240 municipal devices require diagnostic clearing. Emergency services (911/dispatch) experienced zero disruption.
- **Reputational:** Low. Transparent, early communication by Mayor Mike Wiza framed the event as a successful containment narrative.
## Indicators of Compromise
- **Network indicators:** Internal servers online but failing to establish standard communication protocols.
- **File indicators:** None disclosed (malware payloads were intercepted prior to detonation).
- **Behavioral indicators:** Systemic baseline anomalies and suspicious activity across multiple endpoints on the municipal network.
## Response Actions
- **Containment measures:** Immediately revoked access to the affected servers and quarantined all devices showing suspicious activity.
- **Eradication steps:** Isolated the infrastructure and initiated a thorough forensic diagnosis of all ~240 city-owned devices to ensure the environment is entirely clean of threat actor presence.
- **Recovery actions:** Provisioned alternative secure internet access for core personnel and began rebuilding/reestablishing server functionality under a newly implemented, more stringent set of cybersecurity protocols.
## Lessons Learned
- **Key takeaways:** Early detection of network communication anomalies is critical to stopping ransomware before the execution phase. Proactive isolation of entire subnets stops lateral propagation effectively.
- **What could have been done better:** The city is currently analyzing the initial entry vector to determine what security gaps allowed the initial network breach to take place.
## Recommendations
- **Implement Robust EDR:** Deploy Endpoint Detection and Response (EDR) solutions across all 240 municipal devices to ensure real-time visibility into the behavioral anomalies that alerted staff.
- **Enforce Strict Access Controls:** Finalize and maintain the newly implemented "stringent security protocols" to restrict lateral movement paths.
- **Phased Restoration:** Adhere to the city's current strategy of verifying the safety of foundation layers (servers) before restoring individual workstations to avoid accidental reinfection.