Ransomware sends Wood County, Ohio emergency dispatch back to pen and paper

Organization
Wood County, Ohio
Exploit
Ransomware
Industry
Government

Wood County, Ohio detected ransomware on its government computer network on the morning of December 9, 2024 after firewall alerts flagged malicious activity. The county information technology department shut systems down to stop it spreading.

The outage hit the sheriff's office computer aided dispatch system and rippled through several public safety functions, including emergency dispatch, the county jail, road deputies, the civil division that works with the courts, and the Bowling Green Police Division, which lost access to historical records. Dispatchers continued answering 911 calls and coordinating with responders but recorded them on paper. Sheriff Mark Wasylyshyn said the attack had not shut the office down and that every 911 call was being answered.

Officials said fire and emergency services remained available and reported no delays in response times, and noted that longer-serving staff adapted quickly to manual procedures. The county engaged third party cybersecurity and digital forensics consultants and worked with law enforcement, with the FBI taking part in the investigation. In the days after the attack officials did not disclose any ransom demand and pointed to federal guidance discouraging payment.

Wood County subsequently confirmed it had paid about $1.5 million from reserve funds to regain access to its network, a decision the commissioners said followed advice from their outside consultants, who negotiated the demand down from a higher figure. The county said it would notify individuals if the investigation showed personal data had been taken.

Sources