ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

City of Augusta refuses to negotiate with the BlackByte ransomware gang despite facing disruptions

The city of Augusta in the US state of Georgia said that it will not engage with the Blackbyte ransomware group which claimed responsibility for the cyber attack it suffered last month and demanded a huge ransom.On May 21, the mayor of Augusta Garnett Johnson said that the City experienced a major cyber attack which initially appeared as a technical outage. An investigation initiated by the City to understand the cause of the technical outage revealed that external actors had gained unauthorised access to the City’s internal network.A notorious group of threat actors going by the name “BlackByte” later claimed responsibility for the cyber attack and listed the city as a victim on its data leak site. 
 
While the City said that it found no evidence of any sensitive data being compromised, the BlackByte ransomware gang claimed to be in possession of around 10 GB of data exfiltrated from the City’s internal network.According to reports, the leaked documents contain payroll information, contact details, personally identifiable information (PII), physical addresses, contracts, city budget allocation data, and more.The ransomware group has quoted a price of $400,000 for deleting the stolen data and offered to resell it to interested third parties for $300,000. Reports also surfaced that the City has received a ransom demand of $50 million. Mayor Johnson, however, refuted such reports, stating that “recent media reports regarding Augusta, Georgia being held hostage for $50 million in a ransomware attack are incorrect.”In a recent update, the City said that it would not negotiate with the ransomware group responsible for the cyber attack on its computer network. “Over the past week, Augusta, Georgia has continued to work with both its internal Information Technology team and outside cybersecurity specialists to respond to the network disruption that began on May 21, 2023,” Mayor Johnson said.“Our ongoing investigation has determined that an unauthorized actor gained access to certain computer systems. However, it remains the case that Augusta is not in communication with the cybercrime group that has claimed responsibility for this incident,” he added.Currently, the City’s 311 service is functional and is receiving and forwarding service requests to the appropriate departments. Augusta’s transit, utilities, environmental services, finance department, planning & development, and public safety departments are all operating at full capacity as well.The City’s tax department, however, is still not fully operational and is not processing property taxes until further notice. It is only processing motor vehicle transactions, such as tag renewal payments in person.“Again, a thorough investigation is ongoing to determine the extent to which any sensitive personal information may have been impacted by this incident. Augusta remains committed to taking all appropriate actions to notify any impacted individuals identified, once a determination is made.“Our Information Technology Department has executed a path forward to restoration, which has allowed Augusta to continue to serve our residents and visitors, despite our technology challenges,” the City officials added.According to SuspectFile, the BlackByte ransomware gang has demanded a ransom of $2 million and intends to publish around 70 GB of data stolen from the City unless its ransom demand is met. While Mayor Johnson said that the City is still trying to figure out the nature of the stolen data, the ransomware group shared snippets of stolen data that contain sensitive personal, health, and financial information of the city’s residents.

Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543