What happened
The city of Riviera Beach, Florida was hit by ransomware in late May 2019 after a city employee clicked a malicious link in an email. The attack disabled city email, payroll systems and parts of the 911 dispatch infrastructure, forcing staff onto paper processes. In June 2019 the city council voted to pay 65 bitcoin, roughly $600,000, to obtain a decryption key, in addition to about $1 million already approved for new hardware.
How the deception worked
A single employee in the city's administration opened an email and clicked the link inside it, which delivered the payload that encrypted municipal systems. Nothing about the delivery was exotic; the significance is what a small municipality's environment allowed to follow. Flat networks, shared administrative credentials and backups reachable from the same domain meant one workstation compromise propagated to payroll, email, utility billing and dispatch support systems. With no clean restore path and public safety services degraded, the council concluded that paying the ransom was faster than rebuilding, making Riviera Beach the template case for municipal ransom payment.
The control that would have caught it· our reading, not a claim from the sources
Offline, immutable backups tested for restoration change the entire calculus, because the decision to pay was driven by recovery capability rather than by the initial click.
Sources (2)
- Florida city to pay $600K ransom to hacker who seized computer systems weeks agoCNN·cnn.comOpen ↗
- Florida city pays hackers $600,000 after ransomware attackStateScoop·statescoop.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.