Dallas (city) apparently hit with a ransomware attack

hiegtx

Mentor
Premium Subscriber
Joined
May 8, 2004
Messages
11,190
Location
Dallas, TX
The City of Dallas website, as well as several departments, are either offline or experiencing problems due to an apparent ransomware attack.



The computer aided dispatch system, used by Dallas Fire Rescue is also apparently down, and DFR has been in manual dispatch mode mode of the day.,

The Dallas Central Appraisal District system was hit last fall, and apparently an undisclosed figure was paid to the attackers.
 

TexTAC

Member
Joined
Nov 14, 2010
Messages
320
I’ve been listening on the NTIRN system and Dallas Fire is still dispatching manually. They are handling it very professionally despite the situation.
 

ProScan

Software Provider
Premium Subscriber
Joined
Jul 2, 2006
Messages
7,469
Location
Ontario, Calif.
I'm wondering how the City of Dallas or any website can be down due to ransomware over an extended period. Don't they have an IT group that manages the server? Don't they have backup files? If they can access the server root account then it's just a matter of restoring from a backup. If they can't access the server, then I would think that they could get the host provider involved by doing a reboot and wiping the server clean, or substituting another machine.

IMHO, I think it's an inside job. It could be a "trusted 3rd party" that has root access or a contractor working for them.
 
Last edited:

Harold

Member
Premium Subscriber
Joined
Dec 19, 2002
Messages
341
Location
Texas
I'm wondering how the City of Dallas or any website can be down due to ransomware over an extended period. Don't they have an IT group that manages the server? Don't they have backup files? If they can access the server root account then it's just a matter of restoring from a backup. If they can't access the server, then I would think that they could get the host provider involved by doing a reboot and wiping the server clean, or substituting another machine.

IMHO, I think it's an inside job. It could be a "trusted 3rd party" that has root access or a contractor working for them.
I think when they say the Website is down they are referring to the services provide via the website. They cannot access the databases required to provide service via the web.
 

ProScan

Software Provider
Premium Subscriber
Joined
Jul 2, 2006
Messages
7,469
Location
Ontario, Calif.
I think when they say the Website is down they are referring to the services provide via the website. They cannot access the databases required to provide service via the web.
Wouldn't that affect surrounding cities and counties? Are the services hosted on the website? To me, it seems to be the servers.
 

hiegtx

Mentor
Premium Subscriber
Joined
May 8, 2004
Messages
11,190
Location
Dallas, TX
Wouldn't that affect surrounding cities and counties? Are the services hosted on the website? To me, it seems to be the servers.
Dallas being "up" or "down" has no effect on neighboring jurisdictions, as these are not shared systems.

The city's website, DallasCityHall.com, directs you to a Cloudfront 'notification' page. The Dallas PD's website returns a 'service unavailable' page.

Dallas Fire Rescue remains on manual dispatch, with field units having to report en-route, clear, or back in quarters via voice radio via their MDTs. Dallas PD MDT's are also out of service.

911 calls are still being answered, but at times, call takers have had to send a printed 'note' to dispatchers rather than entering call data in the system which then would flow to the actual dispatcher's stations.

Still no posted, or announced, time frame of when issues will be resolved.
 

hiegtx

Mentor
Premium Subscriber
Joined
May 8, 2004
Messages
11,190
Location
Dallas, TX
Latest press release via one of the local TV stations:

add:
 

kv5e

T¹ ÆS Ø
Premium Subscriber
Joined
Dec 19, 2002
Messages
262
Location
127.0.0.1
B0ned and Pwned, all it takes is one unaware human element to make this type of attack possible. Same IT department that lost terabytes of evidentiary case data due to poor backup procedures and resulted in many felony cases getting dismissed from prosecution.

City of DalASS
 

hiegtx

Mentor
Premium Subscriber
Joined
May 8, 2004
Messages
11,190
Location
Dallas, TX
The City of Dallas chief Information security officer has now said it may take "weeks & months" before all systems will be fully restored. DFR is still mostly manual dispatch, with many vehicle MDTs still out of service.


 

Ensnared

Member
Premium Subscriber
Joined
Jan 24, 2004
Messages
4,462
Location
Waco, Texas
B0ned and Pwned, all it takes is one unaware human element to make this type of attack possible. Same IT department that lost terabytes of evidentiary case data due to poor backup procedures and resulted in many felony cases getting dismissed from prosecution.

City of DalASS
Yes, I would agree, "DalAss" is a more fitting name. I needed a belly laugh this morning, thanks.
 

hiegtx

Mentor
Premium Subscriber
Joined
May 8, 2004
Messages
11,190
Location
Dallas, TX
This is still a long way from being over:

"Four weeks into Dallas’ ransomware attack, the city’s communications, outreach and marketing director emailed directions to the mayor and City Council on Wednesday to share little to no details about how it’s being handled."

Full article here:

The DallasNews uses a paywall, limiting the number of views that you can make with a subsription. I have found that for some paywall pages, accessing them via a "Private Window" (that's a term used by FireFox) might aloow access if you are over the limit.
 

hiegtx

Mentor
Premium Subscriber
Joined
May 8, 2004
Messages
11,190
Location
Dallas, TX
Well, Fort Worth has now joined the 'hack my system' party. A number of parts of their networl ssytems have also been hacked. Dallas was hit with a ransomware attack. Apparently, at least at this time, the intrusion into Fort Worth systems doesn't seem to be in the depth where Dallas was impaired.

Dallas is still slowly recovering, parts of one system at a time. The public library is just now getting back up. But other departments are still affected. While city officials have claimed that most of PD & Fire have been restored, I would note that their online pages with active incidents are still offline. The Fire side simply says 'no active incidents. For the PD, you can pull up the Open Data site, but the calls displayed are from March 1st.
 
Top