Baltimore city government was hit by a RobbinHood ransomware attack that forced officials to shut down most servers, disrupted operations across roughly 10,000 government computers, and knocked multiple public services offline. City employees lost access to email, phones, billing systems, and administrative tools, while residents were unable to make online payments for water bills, property taxes, and parking tickets. Emergency services including 911 and 311 remained operational, but departments such as Public Works, Police, and Transportation were pushed to manual workarounds as federal investigators examined the intrusion.
The attackers reportedly demanded 3 Bitcoin per department or 13 Bitcoin for the entire city, with the price set to rise after several days and files allegedly becoming unrecoverable after 10 days. Baltimore refused to pay, and the outage stretched for at least two weeks, making it the city’s second major cyber disruption in little more than a year after an earlier attack affected the 911 system. The incident became a prominent example of how ransomware can paralyze municipal government services and delay routine civic operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Baltimore IT Director Frank Johnson went on leave following criticism from City Council members over his leadership during the city's recovery from the May 2019 ransomware attack. The mayor's office said Deputy IT Director Todd Carter would serve as acting director.
After reports said the Baltimore ransomware attack spread using EternalBlue, Maryland political leaders and U.S. lawmakers sought briefings from the NSA and called for federal assistance. The development intensified scrutiny over whether Baltimore had missed available Microsoft patches and renewed debate over the fallout from leaked NSA-linked exploits.
City leadership decided not to pay the attackers' bitcoin demand despite prolonged service disruptions. The refusal left residents unable to use services such as online payments for water bills, property taxes, and parking tickets for at least two weeks.
Reporting on the Baltimore incident cited research indicating RobbinHood did not self-propagate and was likely deployed manually, such as through PsExec or after compromise of a domain controller. The analysis suggested attackers had already obtained administrative access and staged a public RSA key on targets before encryption began.
Authorities launched a federal investigation into the attack as the city continued responding to the outage. The investigation was underway while Baltimore worked to restore affected systems and services.
The ransomware operators demanded 3 bitcoin per department or 13 bitcoin for the entire city, with the price reportedly set to increase after four days and files becoming irretrievable after 10 days. The total demand was reported at roughly $100,000 at the time.
City officials said most government servers were taken offline as a precaution while emergency services such as 911 and 311 remained operational. The outage disrupted email, phones, billing, hearings, and online payments, forcing staff to use manual workarounds.
On 2019-05-07, attackers deployed RobbinHood ransomware against Baltimore's municipal network, compromising about 10,000 government computers. The attack disrupted core city operations and affected multiple departments, including Public Works, Police, and Transportation.
About 15 months before the May 2019 incident, Baltimore experienced another cyberattack that shut down the city's 911 system for roughly a day. This established that the 2019 event was the city's second major ransomware-related disruption in just over a year.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
baltimoresun.com
Open sourcearstechnica.com
Open sourcebaltimoresun.com
Open sourcenytimes.com
Open sourcenytimes.com
Open sourcevox.com
Open sourcearstechnica.com
Open sourcegizmodo.com
Open sourcearstechnica.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.