Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

Ransomware Attack Wreaks Havoc On Prison Employees And Inmates

Ransomware Attack Wreaks Havoc On Prison Employees And Inmates

Randy Hall By Randy Hall Updated Jul 2024 2 min read Share

Chalk up another first for the hackers.  For the first time that we know of, a successful hacking attack caused prisoners in New Mexico to be confined to their cells for a time.

The Metropolitan Detention Center in Bernalillo County, New Mexico went into lockdown on January 5th of this year (2022) when hackers infiltrated the prison system's network and deployed a malware payload.

For the duration of the system outage the prison cells could not be opened.

While the incident was not reported at the time, details came to light indirectly when the attack and its effects were referenced in court documents. One public defender representing the inmates suggested that their Constitutional rights had been violated due to the incident, which meant that visitations were cancelled.

In addition to the uproar it caused among the prison population, a number of the local government's databases appear to have been corrupted. Until functionality was restored the employees of the prison could not access camera feeds or access any inmate data.

Of course, the physical keys carried by the guards still worked. However, given the situation, the Warden placed the entire facility on lockdown for the duration of the incident.  Full functionality was restored by the afternoon of January 5th.

Few additional details have been revealed about the attack.  We don't even know what sort of malware was deployed.  Only that the system is "still being repaired," according to country officials, and that certain systems are still being impacted.

Unfortunately, the issue has prompted Federal Law Enforcement's involvement as the prison was already under fire for poor conditions.  What happens next is anyone's guess.

It's understandable that the county is being somewhat tight-lipped about the incident. That's especially considering the court case. At least some additional transparency would be appreciated.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime