Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

State of Emergency Declared in Oakland to Combat Ransomware Attack

State of Emergency Declared in Oakland to Combat Ransomware Attack

Randy Hall By Randy Hall Updated Jul 2024 3 min read Share

On Feb. 8, 2023, the City of Oakland suffered a ransomware attack. It forced several city
systems to go offline. Fortunately, it did not affect emergency services. 911 and fire rescue
were still online.

Digital security experts investigated the incident. They assume the attack started with an
email that contained a malicious ransomware program. When a user clicks on a link or
attachment, the ransomware gets into the system and steals valuable data.

Reason for State of Emergency Declaration
Interim City Administrator G. Harold Duffey declared a state of emergency on Feb. 14, 2023. That allows city officials to fast-track procurement to address the situation. They can activate emergency workers faster, too.

Update From the City of Oakland
Not all details are known to date. But several non-critical systems reportedly went offline.
Some services also became unavailable, including the following:

  • Report processing
  • Payment collection
  • Issuance of permits and licenses

A week after the attack, officials are working to put in place their recovery plans. The goal is to restore all affected systems to normal.

They have not announced who was responsible for the attack, though. No one has claimed
responsibility, either.

Ransomware Attacks on the Rise
Ransomware disables systems by encrypting files. It then gives the user a limited time to pay up or risk losing the files. It is easy to get the program into the computer. The challenge is getting paid.

Cybersecurity expert Ahmed Banafa noted that ransomware attacks are rising alongside the increasing use of cryptocurrency.

Hackers had limited options to get paid before cryptocurrency. Regular money transfers can lead to them. They need to provide banks with their data, like names and addresses. With cryptocurrency, they can receive payment privately. Police would have a hard time tracing it to the criminal.

These criminals also like to target the public sector. Unlike private companies, they cannot
justify high budgets for IT. Security experts in Emsisoft said that over 200 US public sector organizations received ransomware threats.

Education and healthcare industries are also vulnerable as they hold valuable data. Patient
details could be stolen and sold to others.

It takes weeks or months to recover from a ransomware attack. Some organizations could not afford that. It takes a lot of time and money to resume normal operations. The best course of action is to prevent an attack.

Security experts suggest having cybersecurity programs. They guard against malware and
computer viruses.

But the best line of defense is knowledge. Companies can invest in employee training.
Employees should learn how attacks happen. That way, they can guard against potential
threats, keeping the organization and its critical data safe.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime