3 min read

CivicLock Ransomware Campaign Hits Eight Midwest Cities, Crippling Municipal Services

A coordinated ransomware campaign has struck municipal governments across the American Midwest, crippling public services in at least eight cities and forcing several to declare cyber emergencies. The attacks, attributed to a ransomware group calling itself “CivicLock,” specifically target the enterprise resource planning (ERP) systems that local governments use to manage payroll, permits, utilities, and public records.

The Attack Pattern

CivicLock exploits a known but frequently unpatched vulnerability in a popular ERP platform used by hundreds of municipal governments. The attackers gain initial access through internet-facing login portals that lack multi-factor authentication, then deploy ransomware that encrypts both the ERP database and associated file servers.

The ransom demands have ranged from $500,000 to $2.5 million per city, payable in Bitcoin. In a particularly aggressive tactic, the attackers also exfiltrate sensitive data before encryption and threaten to publish resident information, including tax records and utility payment histories, if the ransom is not paid.

Cities Affected

Among the affected municipalities, three have publicly confirmed the attacks. The city of Cedar Rapids, Iowa reported that its online permitting system, water billing platform, and employee payroll system were all rendered inoperable. Springfield, Illinois experienced disruptions to its court records system and police dispatch software. Topeka, Kansas reported that its property tax collection system was taken offline during the peak filing period.

The Municipal Cybersecurity Challenge

Local governments are disproportionately vulnerable to cyberattacks due to chronic underfunding of IT security programs. According to a survey by the National Association of State Chief Information Officers, 60 percent of local governments spend less than 5 percent of their IT budgets on cybersecurity, compared to an average of 14 percent in the private sector.

“Municipal IT teams are often stretched thin, managing hundreds of systems with budgets that barely cover basic operations,” said Alan Shark, executive director of the Public Technology Institute. “Security upgrades compete with potholes and fire trucks for funding, and they usually lose.”

Federal Response

CISA has deployed incident response teams to assist affected cities and has issued a joint advisory with the FBI identifying the specific vulnerability exploited by CivicLock. The agencies are urging all local governments using the affected ERP platform to apply the security patch immediately and implement multi-factor authentication on all externally accessible systems.

Should Cities Pay?

The question of whether to pay ransoms remains contentious. The FBI consistently advises against payment, arguing that it funds criminal operations and encourages future attacks. However, several affected cities face the prospect of weeks or months of recovery without payment, during which essential public services remain degraded.

At least two of the affected cities are known to be in negotiations with the attackers, though officials have declined to confirm this publicly. Cybersecurity insurance carriers are also playing an active role in the response, with several reportedly recommending payment in cases where backup restoration is not viable.

The CivicLock campaign underscores the urgent need for increased federal investment in local government cybersecurity and the development of shared security services that smaller municipalities can leverage without building their own security operations centers.


David Hall

David Hall

David is the senior editor at TheCyberMag. He has a background in journalism and has worked with various media outlets, covering topics ranging from threat intelligence and data privacy to cybercrime and cloud security. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.