ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

San Bernardino County in California paid a $1.1m ransom to regain access to encrypted systems

San Bernardino County in the US state of California has paid a $1.1 million ransom to threat actors who targeted the sheriff’s department with a malware attack, forcing it to temporarily shut down most of its systems.Mara Rodriguez, the public information officer at the Sheriff’s Department, said that the network intrusion, first identified on April 7, disrupted the daily operations of the sheriff’s department, and forced it to temporarily take its systems offline to mitigate the impact of the attack.While the security incident was initially reported as a cyber attack, the Sheriff’s Department later confirmed that it involved threat actors injecting malware into the department’s network. Rodriguez, however, did not comment on whether the department suffered a ransomware attack.David Wert, Public Information Officer of San Bernardino County later said that the cybersecurity incident was a ransomware attack. “The network disruption within the San Bernardino County Sheriff’s Department was the result of ransomware that infected portions of the department’s information technology system,” he said.County officials have now confirmed that they paid $1.1 million ransom to the threat actors to get its systems decrypted. According to Wert, the County was prepared for incidents like this and had sought appropriate insurance coverage to deal with such scenarios.“After negotiating with the responsible party, the insurance carrier and the County agreed to a payment to restore the system’s full functionality and secure any data involved in the breach. Insurance covers most of the payment. The County’s share is $511,852.“The decision whether to render payment was the subject of careful consideration. On balance, and consistent with how other agencies have handled these types of situations, this was determined to be the responsible course,” Wert explained.Wert added that a criminal investigation regarding the ransomware attack is ongoing and the Sheriff’s Department is also conducting an internal forensic examination to understand the scope of the security incident and the steps it can take to avoid such incidents in the future.The County has confirmed that no other systems were affected by the ransomware attack and that the incident did not affect the department’s ability to perform its duties toward its people.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543