Ransomware forces the City of Wichita to shut down its network
- Organization
- City of Wichita, Kansas
- Exploit
- Ransomware
- Industry
- Municipal Government
The City of Wichita, Kansas said that on 5 May 2024 certain city systems were encrypted by malware, and that it shut down its computer network to stop the infection from spreading further. In guidance to residents the city described the incident in ransomware terms, explaining that a third party then seeks payment for a key to unlock the affected files.
The shutdown took a broad set of public-facing services offline. Card payment processing stopped, so water and sewer bills, municipal court fees, transit fares and landfill charges had to be paid in cash or by cheque. Library Wi-Fi, catalogues and databases went down, as did airport Wi-Fi and the arrival and departure boards. Livestreams of public meetings and phone lines in several departments were also affected.
Police and fire services continued operating using backup procedures and paper reports. The city suspended automatic payments and said it would not shut off water accounts for non-payment while the incident was ongoing. It also said water treatment and supply systems themselves were unaffected.
Wichita notified federal and local law enforcement and said it was withholding details about the attackers for operational security reasons. Systems were to be brought back on a staggered basis, and the city offered no recovery timeline. In its first week of updates the city said it had not yet determined what resident data, if any, had been taken.