2019 Baltimore ransomware attack

Last reviewed:

The 2019 Baltimore ransomware attack was a significant cyber incident that affected the city's computer systems, disrupting various municipal services. The attack involved ransomware, a type of malicious software designed to block access to a computer system until a sum of money is paid. As of 2019, the attack had a considerable impact on Baltimore's operations, affecting services such as email, payment systems, and property transactions. The incident highlighted the vulnerabilities in municipal cybersecurity and the potential consequences of ransomware attacks on public infrastructure.

Overview

The Baltimore ransomware attack occurred in May 2019, targeting the city's computer systems and causing widespread disruption. The attackers used ransomware to encrypt files, demanding a ransom in Bitcoin to restore access. The attack affected various city services, including email systems, payment processing, and property transactions. Baltimore officials refused to pay the ransom, opting instead to restore systems through backups and other recovery methods. The attack underscored the importance of robust cybersecurity measures for municipal governments and the potential risks posed by ransomware.

History

The attack began on May 7, 2019, when Baltimore's IT department detected unusual activity on the city's computer network. The ransomware, identified as RobbinHood, encrypted files on infected systems, rendering them inaccessible. The attackers demanded approximately 13 Bitcoin, equivalent to around $76,000 at the time, to decrypt the files. Baltimore's mayor, Bernard C. "Jack" Young, announced that the city would not pay the ransom, citing a policy against rewarding criminal behavior.

The attack disrupted numerous city services, including email communication, online payment systems for water bills and parking tickets, and real estate transactions. The city's recovery efforts involved restoring systems from backups and implementing additional security measures to prevent future attacks. The recovery process was lengthy and costly, with estimates of the total cost reaching over $18 million, including system restoration, lost revenue, and additional cybersecurity measures.

Technical characteristics

The ransomware used in the Baltimore attack was identified as RobbinHood. This malware encrypts files on infected systems, appending a ".rob" extension to the encrypted files. RobbinHood is known for targeting Windows-based systems and is typically deployed through compromised remote desktop protocol (RDP) connections or phishing emails. Once executed, the ransomware encrypts files and displays a ransom note demanding payment in Bitcoin for the decryption key.

RobbinHood is notable for its ability to disable security tools and services, making it challenging to detect and mitigate. The ransomware also attempts to delete shadow copies, which are backup copies of files, to prevent recovery without paying the ransom. The malware's encryption algorithm is robust, making decryption without the key difficult.

Infection vector

The exact attack vector used in the Baltimore ransomware attack remains unclear. However, ransomware attacks commonly exploit vulnerabilities in remote desktop protocol (RDP) services, phishing emails, or software vulnerabilities. In the case of Baltimore, it is suspected that the attackers gained access through a compromised RDP connection or a phishing email that tricked a user into executing the malware.

RDP is a protocol that allows remote access to a computer, and it is often targeted by attackers due to its widespread use and potential for misconfiguration. Phishing emails are another common method for delivering ransomware, as they can trick users into clicking on malicious links or downloading infected attachments.

Notable campaigns

The 2019 Baltimore ransomware attack is one of several high-profile ransomware incidents targeting municipal governments. Similar attacks have occurred in other cities, including Atlanta and New Orleans, highlighting the growing threat of ransomware to public infrastructure. These attacks often result in significant disruption to city services and can incur substantial recovery costs.

In response to these incidents, many municipalities have increased their focus on cybersecurity, implementing measures such as regular security assessments, employee training, and improved backup and recovery processes. The Baltimore attack serves as a case study for other cities, emphasizing the importance of proactive cybersecurity measures and the potential consequences of ransomware attacks.

Detection and mitigation

Detecting and mitigating ransomware attacks requires a multi-layered approach to cybersecurity. Organizations should implement robust security measures, including firewalls, intrusion detection systems, and antivirus software, to detect and block ransomware before it can execute. Regular security assessments and vulnerability scans can help identify and address potential weaknesses in the network.

Employee training is also crucial, as phishing emails are a common method for delivering ransomware. Training programs should educate employees on recognizing phishing attempts and the importance of reporting suspicious activity.

In the event of a ransomware attack, having a comprehensive backup and recovery plan is essential. Regularly backing up critical data and storing it offline can help organizations recover without paying the ransom. Additionally, maintaining up-to-date software and applying security patches promptly can reduce the risk of exploitation by ransomware.

Timeline of the 2019 Baltimore Ransomware Attack

Impact of the Ransomware Attack on City Services

See also

Sources

Categories: Malware | Incidents
Last updated: September 16, 2026