Anne Arundel County closed buildings after ransomware attack on its network
- Organization
- Anne Arundel County, Maryland
- Exploit
- Ransomware
- Industry
- Government
Anne Arundel County, Maryland, closed its government buildings on Monday, February 24, 2025 while it responded to a cyberattack on its computer network. The county said it had identified suspicious activity affecting certain systems on February 22 and treated the closure as a precaution while investigators worked.
Several services were interrupted. Customer service centers run by the Department of Aging and Disabilities shut, though phone lines stayed open, recycling centers and the landfill closed, and AARP tax preparation at senior activity centers was suspended. Curbside collection continued, and county libraries, public schools, senior activity centers and recreation and parks facilities operated normally. Emergency and non-emergency call lines remained available. Employees eligible to telework did so using internet based systems. Buildings reopened on Tuesday, February 25.
County Executive Steuart Pittman described the shutdown as a step to protect county systems. The Office of Information Technology worked with public safety officials and outside cybersecurity specialists, and federal law enforcement and state agencies were notified.
The county later confirmed that the intrusion was a ransomware attack by an external actor and that an unauthorized party had access to a limited part of its network between January 28 and February 22, 2025, during which certain files were accessed or downloaded. The county said the affected material related to people who received treatment and services from its Department of Health and could include names, addresses and medical diagnoses. No financial information was involved, and the county said it found no evidence the data had been published.