First reportedMay 7, 2019
ActivityMay 7, 2019
Last updatedFeb 2, 2026, 12:00 AM UTC
Record confidencemed

Key facts

Affected

  • City of Baltimore government services
  • Residents and businesses dependent on city services

Initial access

  • unknown

Impact

  • encryption
  • service_disruption
  • financial_loss

Attribution

unknown low confidence

Cited sources focus on municipal impact and costs; definitive public attribution is not provided in the included materials.

CVEs and ATT&CK

CVEs

ATT&CK techniques

  • T1486: The incident involved ransomware encryption leading to service disruption and recovery efforts.

Mitigations

Now

  • Maintain offline/immutable backups and regularly test restoresEnables recovery without paying ransom and reduces business downtime when systems are encrypted or wiped.

Soon

  • Segment networks and restrict administrative privilegesSlows attacker movement and limits the blast radius of ransomware deployment across the enterprise.

Later

  • Harden endpoints/servers with EDR and restrict remote admin toolsImproves detection and blocking of ransomware behaviors and common lateral-movement mechanisms used to deploy payloads.

Detection ideas

Detect mass file encryption or destructive file operations

Alert on rapid renames/overwrites across many directories, creation of ransom notes, and high-entropy writes by unfamiliar processes.

Data sources: EDR telemetry, File integrity monitoring, Windows Security Event Logs

Detect lateral movement and remote execution used for ransomware deployment

Look for PsExec/SMB service creation, remote scheduled tasks, or WMIC usage followed by execution of the same binary on multiple hosts.

Data sources: EDR telemetry, Windows Security Event Logs, Network flow logs

Sources