The City of Dallas said the Royal ransomware gang gained access to municipal systems on April 7, 2023, spent weeks conducting surveillance, and exfiltrated about 1.17 TB of data before launching ransomware at 2 a.m. on May 3. The attack damaged hundreds of servers and more than a thousand endpoint devices, disrupting critical city operations including public safety dispatch, with police and ambulances reportedly sent to incorrect locations. Dallas activated its incident response plan, brought in outside cybersecurity firms, and coordinated with the FBI and CISA; more than 90% of affected services were restored within 18 days, and the city later approved $8.5 million for recovery and breach-notification work.
Reporting on the incident said the intrusion exposed longstanding technical debt inside city systems, including outdated and unsupported software that increased risk despite recent gains in cybersecurity staffing and spending. The disruption echoed earlier ransomware damage in Atlanta, where city networks were hobbled by an attack linked to SamSam, forcing widespread shutdowns and recovery efforts with federal and private-sector assistance. Together, the incidents show how major U.S. municipalities remain high-value ransomware targets when internet-facing systems, patching gaps, and legacy infrastructure leave essential public services vulnerable.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The city approved $8.5 million to support ransomware recovery and breach notification efforts following the Royal attack. A later after-action report also cited technical debt, outdated systems, and unsupported software as factors that increased risk.
Within 18 days of the May 3 attack, Dallas had restored more than 90% of impacted services. The recovery followed major disruption to city operations caused by the Royal ransomware incident.
After the ransomware attack, Dallas activated its incident response plan and worked with external cybersecurity firms, the FBI, and CISA. The incident ultimately damaged hundreds of servers and more than a thousand endpoint devices, with about 1.17 terabytes of data exfiltrated.
Royal deployed ransomware against Dallas at about 2 a.m., disrupting critical municipal services. The attack affected public safety dispatch and contributed to police and ambulances being sent to incorrect locations.
According to a later after-action report, the Royal ransomware gang infiltrated Dallas municipal networks and began surveillance inside the environment. The attackers remained in the network for weeks before launching ransomware.
Atlanta officials said they were working continuously to recover from the attack with help from the FBI, the Department of Homeland Security, and private-sector partners. Investigators assessed the scope of the incident, and experts cited signs consistent with SamSam ransomware.
Atlanta's computer network was hit by a ransomware attack that encrypted some city data and disrupted numerous city applications. The city shut down many systems as a precaution, while emergency response systems, water safety, and airport operations were reported unaffected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcetheregister.com
Open sourcetherecord.media
Open sourcestatescoop.com
Open sourceapnews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.