CiberLATAMbywhalemate

Stevens Point, Columbus face ransomware fallout

Stevens Point says it stopped a ransomware attempt before data was stolen. Columbus is still in court over a 2024 data breach.

Whalemate Labs · AI-assisted researchPublished:2 min read

Stevens Point, Wisconsin, said it stopped a ransomware attempt before the code ran and found no evidence that data was stolen. In a separate case, Pennington County said all departments were back online after a July attack, although some systems and public services were still limited during recovery.

Stevens Point, Wisconsin, said it stopped a ransomware attempt before the code could run and found no evidence that information was stolen. The city also said emergency services kept operating normally throughout the incident, while its IT team isolated and quarantined affected devices, which represented about 1% of municipal hardware.

What happened in Stevens Point?

The city described the episode as a thwarted ransomware attempt and said it contained the threat before it spread further. Officials quoted by WSAW said the compromised machines were separated from the rest of the network and placed in quarantine to limit the impact.

WSAW also reported that the administration expected it would take about two weeks to fully restore municipal operations. In the meantime, email and phone service were still experiencing delays and intermittent outages, although emergency services were not affected.

What is known about the Columbus case?

The Ohio Tenth District Court of Appeals overturned an initial dismissal of a class-action lawsuit against Columbus and allowed the case to move forward. The trial judge had ruled that the city was immune as a political subdivision.

The Columbus Dispatch reported that Columbus detected the attack on July 19, 2024, and disconnected its IT network. It also said that in August, cybercriminals tried to auction off the stolen data and later posted part of it on the dark web.

According to NBC4 Columbus via Yahoo News, the 2024 attack led to the dark web leak of private and sensitive information belonging to half a million people. In the court filing, The Columbus Dispatch added that plaintiffs argue the city failed to follow industry standards and federal security guidance, downplayed the impact, and delayed remediation, although those are allegations in the lawsuit and not proven facts.

How did Pennington County fare after the July attack?

Pennington County said all of its departments were back online after the July ransomware attack, although some systems and public services remained limited during recovery. The official update showed a partial return to normal, with restrictions still in place for some services.

The contrast between the cases points to three different situations in local U.S. governments. Stevens Point said it stopped an attempt before it was executed, Pennington County described an ongoing recovery after a confirmed attack, and Columbus is facing an open legal case over a 2024 incident that exposed data on the dark web.

Sources

View all