Cleveland cyberattack forces city officials to cut network access
Hackers have breached the City of Cleveland, Ohio, forcing officials to cut off access to government IT systems to try and contain the damage.

Image by Sean Pavone | Shutterstock
Hackers infiltrated the government networks of the City of Cleveland, Ohio, forcing officials to cut off public access to City Hall on Wednesday. Security teams had already shut down IT systems during Monday's attack in an attempt to contain the damage.
In an update on the social media platform X on Tuesday evening, Cleveland officials said that security teams first became aware of โabnormalitiesโ in the cityโs IT environment on Monday.
After taking โprecautionary actions to contain those abnormalitiesโ which involved cutting off access to city systems, the City said it has been busy โinvestigating the nature and scope of the incident.โ
The update also made sure to inform the Cityโs more than 360,000 residents that all emergency services, including 911 call centers, police and fire departments, as well as EMS services are all operating normally.
Cleveland is Ohioโs second largest city after Columbus, the state capital.
According to the latest update, Clevelandโs City Hall and ErieView Plaza, shuttered in the wake of the attack, will reopen on Wednesday at 11:00 a.m. CT โ but only to employees.
By late Wednesday, the city decided to close down City Hall to non-employees, at least for the rest of the week, and has advised residents to postpone City Hall business until IT systems are fully operational.
๐๐ถ๐๐ ๐ผ๐ณ ๐๐น๐ฒ๐๐ฒ๐น๐ฎ๐ป๐ฑ ๐๐๐ฏ๐ฒ๐ฟ ๐๐ป๐ฐ๐ถ๐ฑ๐ฒ๐ป๐ ๐จ๐ฝ๐ฑ๐ฎ๐๐ฒ
undefined City of Cleveland (@CityofCleveland) June 11, 2024
Please see below for updated information & FAQs about the City of Cleveland cyber incident.
City Hall and Erieview Plaza will re-open Wednesday, June 12th on a delayed start of 11am. pic.twitter.com/8ojgHBZIxM
As for the possibility of threat actors having gained unauthorized access to sensitive data, officials have confirmed that โcertain City dataโ was unaffected, including
- Taxpayer information held by the CCA.
- Customer information held by Public Utilities.
"Cyberattacks on cities across the United States have been an escalating issue, exemplified by the recent incident that forced Cleveland City Hall to shut down yesterday,โ said Paul Laudanski, Director of Security Research at cybersecurity solutions firm Onapsis.
โWhile it is good that police, fire, and emergency medical services are still functioning in Cleveland, cyber incidents like this have the potential to disrupt public services,โ Laundanski pointed out.
Luckily, other government services said to have escaped major disruptions include Clevelandโs Department of Public Utilities (water and power), Municipal courts, Trash collection, Recreation department, and Port control at the Hopkins and Burke Lakefront Airports, as well as the 311 resident information line.
The city says it collaborating with several key partners who provide expert knowledge and deep experience in this work, and will continue to post updates on social media.
Update for Visitors to Building & Housing at City Hall today Wednesday, June 12th. pic.twitter.com/JSRIwSm68o
undefined City of Cleveland (@CityofCleveland) June 12, 2024
So far, no cybercriminal group has claimed the attack. Cybernews has reached out to Cleveland's Mayor Justin Bibb's office and will follow the story.
Municipalities are prime targets
Among Western nations, smaller and midsize cities with populations below the million mark have been a steady target for ransomware groups over the past few years.
Laundanski explained that โState and local governments are prime targets for cybercriminals due to their outdated security systems and shortage of skilled cybersecurity professionals.โ
โThe insufficient allocation of resources towards cybersecurity heightens the vulnerabilities of these organizations,โ he said.
Full restoration of IT networks for these compromised municipalities can often take weeks, if not months, with some government officials choosing to pay the ransom demand โ although not a practice supported by the FBI.
Previous attacks include the two California cities of Modesto and Oakland last February, the City of Dallas, Texas, in May, and the City of Leicester, England, in March.
All the attacks mentioned were eventually claimed by active ransomware gangs within weeks of them taking place., including the Snatch cybercriminal gang, the Play cartel, the Royal gang (now known as BlackSuit), and the INC Ransom group, respectively.
All the ransomware outfits boasted of having exfiltrated troves of sensitive data during the attacks, eventually leaking the alleged caches onto the dark web when negations for ransom demands eventually failed.
Laundanski said the Cleveland attack further highlights the persistent vulnerabilities in municipal cybersecurity, and underscores the need for robust defensive measures.
โAddressing this challenge requires a multi-faceted approach beginning with having the right skilled professionals, and fostering a strong culture of cybersecurity awareness,โ he said.
Proactive measures to improve cyber resiliency suggested by Laundanski, include โenhancing detection capabilities, as well as partnering with MS-ISAC to help with security assessments and plan of action.
The Multi-State Information Sharing and Analysis Center (MS-ISAC) is part of the non-profit Center for Internet Security (CIS), and is backed by the US Cybersecurity and Infrastructure Security Agency (CISA).