Ransomware attack knocked City of Flint payment and phone systems offline

Organization
City of Flint, Michigan
Exploit
Ransomware
Industry
Municipal Government

The City of Flint, Michigan said a ransomware attack in the early hours of August 14, 2024 disrupted its internal network and knocked several public-facing services offline. The city's BS&A municipal management and billing platform became unavailable, which stopped online and credit card payments for water, sewer and tax bills and left cash and check as the only accepted methods.

Email access was limited for some employees, and the phone and voicemail systems suffered gaps in service. GIS mapping tools also went down. Emergency services including 911, dispatch, police and fire operations were unaffected, as were public works and the city's public health office. Officials said residents would not face late fees, penalties or water shutoffs while the payment systems were down.

Flint's technology staff worked with outside cybersecurity specialists, the FBI and the state attorney general's office. As of August 19, 2024 no group had claimed responsibility and the city had not determined whether personal data was taken. Mayor Sheldon Neeley said the city was working to resolve the problem and to minimise disruption for Flint residents.

Partial restoration of critical internal functions began on August 20. The city said it installed a redesigned network with next generation firewalls by August 26 and had recovered the majority of its key data. Online bill payment returned on September 6 through a third-party portal, accompanied by a grace period on late fees and shutoffs that ran until October 7, 2024.

Sources