WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Ransomware Incident Awareness – Timeline of Events in Fulton County Incident and Main Takeaways for Utilities
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partnerships
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Ransomware Incident Awareness – Timeline of Events in Fulton County Incident and Main Takeaways for Utilities

Author: Chase Snow

Created: Tuesday, March 5, 2024 - 19:02

Categories: Cybersecurity

Fulton County, the largest county in Georgia, is still recovering from its January cyber incident. LockBit, the ransomware gang that took credit for the attack, posted a timer on its criminal website demanding payment – all this despite having its criminal infrastructure disrupted by the FBI in late February. LockBit then removed the county from its site and Fulton County “called their bluff” publicly stating they made no payment to the criminals.

This highlights two important takeaways – the extent to which cyber incidents affect critical infrastructure such as municipalities and utilities, and how criminal ransomware gangs often bluff their way to receiving payment. More than a month later, county officials are still working to restore downed phone lines and online systems. County chairman Robb Pitts stated that its online systems for paying water bills has been restored, but not for property tax payments. County email systems are back online, although only half of the phone lines in county offices are working. For more information regarding the Fulton County incident, access Security Week. 

 

Related Resources

Tip of the Week – May 14, 2026

May 14, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 14, 2026)

May 14, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) Non-Human Identities (NHIs) Are Growing Faster Than Most Security Programs

May 14, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar