• 3 minuti
  • Pubblicato

Stevens Point stops ransomware cold before damage

Barbara Carminati Autrice di cybersecurity e privacy QWERTYmag

Scritto da Barbara Carminati

Stevens Point stops ransomware cold before damage QWERTYmag © www.qwertymag.it
Stevens Point stops ransomware cold before damage © www.qwertymag.it

Stevens Point IT staff cut off a ransomware attack before it could run. No resident data was lost. City services are bouncing back fast after last week's breach.

Early on September 23, Stevens Point's city network tripped alarms. Several servers glitched. IT staff moved fast. They isolated suspect machines and started checks. The threat was real. Someone tried to launch ransomware inside the city's system.

But the attack failed. No files were encrypted. No data was stolen. The city's IT team blocked the ransomware before it could run. That quick action kept resident and employee information safe. The response followed the Agenzia per la Cybersicurezza Nazionale guidelines for public sector cybersecurity.

  • Official statements and investigation

    For days, city leaders called the problem "intermittent technology issues." Inside, staff knew it was a cyberattack. Nearly a week later, Mayor Mike Wiza spoke up. "We now believe that the City was a target of a ransomware attempt. Our existing security, monitoring and professional staff were able to block the attempt before it was able to execute." That was the first public confirmation. The city still hasn't said how the attacker got in, who did it, or how long they were inside. The investigation is still running. Wisconsin Emergency Management and other agencies are helping.

    Only about 1% of city devices were affected. Later checks showed those machines were not actually compromised. Full system recovery is expected within two weeks. That's much faster than most public sector ransomware cases.

    Emergency services and critical city functions remained operational throughout the incident, demonstrating the effectiveness of network segmentation and incident response protocols.

    Agenzia per la Cybersicurezza Nazionale
  • Impact on services and emergency response

    Police, fire, and utilities kept working. The Emergency Operations Center opened on the night of September 23. At first, it included only first responders and utilities. Soon, department heads joined in. Emergency Management Coordinator Justin Malin said the EOC was key for keeping services running and resources organized. The city's approach matches European rules from AGCOM and ACN. Those rules stress the need to keep emergency communications and core services going during cyber incidents.

    City staff teamed up with UW-Stevens Point, Portage County IT, and state agencies. They checked the damage and started repairs. Some city services slowed down or paused. But now, officials say everything could be back to normal by the end of this week or early next week. That's sooner than the two-week window first feared. The city also told all required state and federal agencies about the breach, following public administration reporting rules.

  • How Stevens Point compares to other ransomware cases

    Stevens Point's story is different from cities hit hard by ransomware. In Columbus, a ransomware attack led to a class action lawsuit after the personal data of 500,000 residents was exposed, as reported earlier. Stevens Point stopped the threat before any data leaked. That shows how much difference fast action and strong security make.

    The city hasn't shared the technical details of its defense. But the results are clear. No resident or employee data was lost. Recovery is moving fast. This case proves that with good monitoring, skilled staff, and quick decisions, even targeted ransomware can be stopped before it causes real harm. Other public institutions should take note. Preparation and openness are now basic survival tools against constant cyber threats.

  • Articoli correlati