---
title: 'Coordinated Ransomware Attack' in Texas Hits 23 Local Governments - from BLEEPINGCOMPUTER
description: The continued scourge of ransomware attacks targeting municipalities across the United States continues.  This time, 23 confirmed attacks reported last week by entities in Texas.  VLCM recommends that local municipalities and other entities in Utah should stay informed, remain vigilant and follow previously-released guidance from the US Cybersecurity and Infrastructure Agency (CISA), Multi-State Information Sharing and Analysis Center (MS-ISAC), National Governors Association (NGA) and the National Association of State Chief Information Officers (NASCIO) in order to prevent attacks.
image: https://blog.vlcm.com/hubfs/ransomware-2.jpg
---

[![VLCM Getting IT Right Logo](https://blog.vlcm.com/hubfs/_vlcmlogos/vlcm%20tagline.svg "VLCM Getting IT Right Logo")](https://www.vlcm.com)

# 'Coordinated Ransomware Attack' in Texas Hits 23 Local Governments - from BLEEPINGCOMPUTER

![](https://blog.vlcm.com/hubfs/vlcm.png)

Joseph Warner

 August 19, 2019

<https://www.linkedin.com/sharing/share-offsite/?url=https://blog.vlcm.com/blog/texas-ransomware-attack> <http://www.facebook.com/sharer.php?u=https://blog.vlcm.com/blog/texas-ransomware-attack> <http://twitter.com/share?text=&url=https://blog.vlcm.com/blog/texas-ransomware-attack> [mailto:?subject=[SUBJECT]&body=Check%20out%20this%20site%20https://blog.vlcm.com/blog/texas-ransomware-attack](mailto:?subject=[SUBJECT]&body=Check%20out%20this%20site%20https://blog.vlcm.com/blog/texas-ransomware-attack) <https://blog.vlcm.com/blog/texas-ransomware-attack>

"The continued scourge of ransomware attacks targeting municipalities across the United States continues.  This time, 23 confirmed attacks reported last week by entities in Texas.  VLCM recommends that local municipalities and other entities in Utah should stay informed, remain vigilant and follow [previously-released guidance](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.us-cert.gov%2Fsites%2Fdefault%2Ffiles%2F2019-07%2FRansomware_Statement_S508C.pdf&data=02%7C01%7Cjdoucette%40vlcmtech.com%7C88f7665c74e0409dce3f08d724af3010%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637018207166197020&sdata=8d9g5duyAAH%2B7oZ%2B70%2FIdH843FoQX8KW3RaZ01MWW70%3D&reserved=0) from the US Cybersecurity and Infrastructure Agency (CISA), Multi-State Information Sharing and Analysis Center (MS-ISAC), National Governors Association (NGA) and the National Association of State Chief Information Officers (NASCIO) in order to prevent attacks."

![ransomware-2](https://blog.vlcm.com/hs-fs/hubfs/ransomware-2.jpg?width=1200&name=ransomware-2.jpg)

*Originally posted on* [BLEEPINGCOMPUTER](https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.bleepingcomputer.com%2F&data=02%7C01%7Cjdoucette%40vlcmtech.com%7C88f7665c74e0409dce3f08d724af3010%7Cd4c6fc04732f42258730f686adab6818%7C1%7C0%7C637018207166207012&sdata=b09J0LMNt3jKbXvB4tWEdj0bYPgZ39sK8PDt8eHSMYY%3D&reserved=0)

Texas is currently fighting an unprecedented wave of ransomware attacks that has targeted local government entities in the state, with at least 23 impacted by the attacks.

Details are at a minimum at the moment as the Department of Information Resources (DIR) leads the response and investigation into the attacks. Texas released a brief notification advising affected local jurisdictions to call the state's Division of Emergency Management for assistance.

## 23 may not be the final count

The attacks started in the morning of August 16 and based on the collected evidence appear to have been conducted by a single threat actor.

The number of confirmed victims is 23 and the department believes that this is how many entities were "actually or potentially impacted;" all of them have been notified.

 

The origin of this attack is currently unknown, but is being investigated by local Texas authorities such as the DIR, Texas Division of Emergency Management, and Texas Military Department.

Also involved in the investigation are federal agencies such as the Department of Homeland Security, Federal Bureau of Investigation – Cyber, and Federal Emergency Management Agency (FEMA).

In its [original statement](http://dir.texas.gov/View-About-DIR/Article-Detail.aspx?id=207) released late Friday, DIR says that while investigations into the origins of the attack are ongoing, their main priority is to assist in the response and recovery of affected entities.

> "Currently, DIR, the Texas Military Department, and the Texas A&M University System’s Cyberresponse and Security Operations Center teams are deploying resources to the most critically impacted jurisdictions."

Additional resources will be provisioned if they are requested, DIR added, noting that the Texas Division of Emergency Management (TDEM) is assisting the effort by coordinating state agency support through state's operations center.

DIR is leading the response to what it calls a "coordinated ransomware attack" but does not disclose which organizations are impacted. This is because of security concerns.

Elliot Sprehe, press secretary for the department, told [KUT](https://www.kut.org/post/ransomware-attack-hits-local-governments-texas), Austin's NPR Station that DIR was trying to confirm the total number of affected entities.

"It looks like we found out earlier today, but we’re not currently releasing who’s impacted due to security concerns,” Sprehe told the public radio station.

In an updated statement on Saturday, DIR [said](https://dir.texas.gov/View-About-DIR/Article-Detail.aspx?id=210) that the systems and networks of the State of Texas have not been affected by this attack. 

 

Until more details emerge, it remains unclear the strain of file-encrypting malware responsible for the attack and the perpetrator(s) ransom demand.

Hopefully, a proper backup system was implemented and current efforts to restore activity to normal relate only to recover the data from the safe copies.

## Ransomware is big in U.S.

Ransomware incidents have increased lately in the U.S., and the government sector is a frequent target. And it makes sense when more and more administrative entities decide to pay the ransom, which may get as high as half a million dollars.

[Telemetry data](https://www.bleepingcomputer.com/news/security/us-accounts-for-more-than-half-of-worlds-ransomware-attacks/) from security company Malwarebytes reveals the the U.S. has been at the receiving end of ransomware attacks more than any other country in the world., accounting for 53% of the global incidents.

In June, cybercriminals demanded and got paid in bitcoins worth a little [over $1 million](https://www.bleepingcomputer.com/news/security/attackers-earn-over-1-million-in-florida-ransomware-attacks/) at that time, from just two attacks in Florida.

Organizations in other states have also been hit by ransomware [recently](https://www.bleepingcomputer.com/news/security/ransomware-attacks-grow-rampant-paying-still-not-a-good-option/): the Town of Collierville in Tennessee, Onondaga County libraries in New York, Henry County in Georgia, [school districts](https://www.bleepingcomputer.com/news/security/malware-attack-delays-alabama-districts-school-year-twice/) in Louisiana and Alabama.

The map below shows file-encrypting incidents impacting medical, educational and government organizations across the US:

 

 

What all these attacks should have in common is a backup restore procedure and not paying the cybercriminals.

**Copyright VLCM   |  All Rights Reserved  |  [Privacy](https://www.vlcm.com/privacy)**

- [![facebook icon](https://blog.vlcm.com/hs-fs/hubfs/i-img/social-fa.png?t=1444107731905&width=22&name=social-fa.png "facebook icon")](https://www.facebook.com/VLCMtech/)[![linkedin icon](https://blog.vlcm.com/hs-fs/hubfs/i-img/social-in.png?t=1444107731905&width=22&name=social-in.png "linkedin icon") ](https://www.linkedin.com/company/valcom-vlcm-) [![instagram icon](https://blog.vlcm.com/hs-fs/hubfs/i-img/social-phot.png?t=1444107731905&width=22&name=social-phot.png "instagram icon") ](https://www.instagram.com/vlcmtech/) [![twitter icon](https://blog.vlcm.com/hs-fs/hubfs/i-img/social-twi.png?t=1444107731905&width=22&name=social-twi.png "twitter icon") ](https://twitter.com/vlcmtech)[![shopping cart icon](https://blog.vlcm.com/hs-fs/hubfs/cart.png?width=24&name=cart.png "shopping cart icon") ](https://usm.channelonline.com/valcomslc/storesite/Login/?destination=/valcomslc/storesite/Search/Category/index.co)

![](https://px.ads.linkedin.com/collect/?pid=494756&fmt=gif)