Alabama says ‘cybersecurity event’ could disrupt state government services

Avatar

Alabama’s governor said the state is responding to a “cybersecurity event” and is advising residents to be patient with any disruptions to government website access or other communications.

Gov. Kay Ivey made the announcement on Monday morning, and local media reported later in the day that the government’s response was ongoing. Ivey’s statement said “some state employee usernames and passwords were compromised,” but “it is currently believed that no Alabamian’s personally identifiable information has been retrieved.”

The incident was first detected on May 9, Ivey said, and teams from the state Office of Information Technology (OIT) “have been working around-the-clock to identify and mitigate any impacts.” OIT created a web page specifically for updates.

Investigators don’t yet know the full scope of the attack or who is responsible, Ivey said, but her statement noted that “all state employees are being reminded to be cautious for potentially malicious emails.”

As is typical for this kind of event, the state government said it brought in a third-party cybersecurity firm to help with incident response.

As of early Tuesday morning, the state had not provided further updates.

Cyberattacks on state and local government agencies have become common in recent years. Examples include Rhode Island’s benefits system, Oregon’s environmental agency and the office of Virginia’s attorney general, as well as the city governments of Abilene and Mission in Texas, and systems in a Pennsylvania county.

CybercrimeGovernmentNewsNews Briefs
Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Joe Warminsky

is the news editor for Recorded Future News. He has more than 25 years experience as an editor and writer in the Washington, D.C., area. He previously he helped lead CyberScoop for more than five years. Prior to that, he was a digital editor at WAMU 88.5, the NPR affiliate in Washington, and he spent more than a decade editing coverage of Congress for CQ Roll Call.

 

Total
0
Shares
Previous Post

Marks & Spencer confirms customer data stolen in cyberattack

Next Post

Malicious PyPI Package Posing as Solana Tool Stole Source Code in 761 Downloads

Related Posts

Deepfake Defense in the Age of AI

The cybersecurity landscape has been dramatically reshaped by the advent of generative AI. Attackers now leverage large language models (LLMs) to impersonate trusted individuals and automate these social engineering tactics at scale.  Let’s review the status of these rising attacks, what’s fueling them, and how to actually prevent, not detect, them.  The Most Powerful Person on the
Avatar
Read More

Ongoing Cyber Attacks Exploit Critical Vulnerabilities in Cisco Smart Licensing Utility

Two now-patched security flaws impacting Cisco Smart Licensing Utility are seeing active exploitation attempts, according to SANS Internet Storm Center. The two critical-rated vulnerabilities in question are listed below -  CVE-2024-20439 (CVSS score: 9.8) - The presence of an undocumented static user credential for an administrative account that an attacker could exploit to log in to an
Avatar
Read More