Cybersecurity specialist analyzes city’s response to ransomware attack and future steps

COLUMBUS, Ohio (WSYX) — Columbus is steadily recovering from a ransomware attack that occurred a month ago.

According to Luke Connolly, a threat analyst with Emsisoft, terabytes of data appearing on the dark web indicate that the attackers had long-term access to the city’s computer systems. Connolly noted that this is one of the largest breaches he’s encountered.

RELATED | Ginther on ransomware attack miscommunication: ‘The buck stops with me’

When ABC 6 inquired about private citizen data being compromised—something Mayor Ginther had previously denied, stating only employee records were affected—Connolly responded:

“I’m unsure what led the mayor to declare that any stolen data was ‘corrupt,’ as I reviewed numerous files on the Rhysida dark web site earlier this week,” Connolly said. “The data dump contains many readable files, including employee evaluations, meeting minutes, RFPs, and reports.”

Mayor Ginther clarified during his Saturday press conference that he didn’t have all the facts when he initially told ABC 6 that no private citizen data had been exposed.

“That’s not a statement I would have made. I’m not a politician,” Connolly commented. “He said he didn’t have enough information to make that statement?”

Connolly also outlined the next steps for the city to prevent future incidents.

“They’ll need to conduct an extensive forensic investigation to determine how the attackers gained access, how long they were inside the system, and which specific servers and computers were compromised,” Connolly explained. “Significant remediation efforts will be necessary to ensure that the attackers can’t regain access to the network or any of its computers.”

Given the scale of the breach, Connolly said this process could take several weeks.

The city is now providing credit monitoring services for those affected.

More Articles & Posts