Incident: Cyberattacks Disrupt Public Services in New Mexico County

Published Date: 2022-01-13

Postmortem Analysis
Timeline 1. The software failure incidents in New Mexico's most populous county, including the cyberattack on Albuquerque's public school system and the ransomware attack on Bernalillo County, occurred in early January 2022 as per the article published on January 13, 2022 [Article 123219].
System 1. Albuquerque public school system's computer systems 2. Bernalillo County's computer systems 3. Cameras at the local jail in Bernalillo County [Article 123219]
Responsible Organization 1. The cybercriminals carrying out the ransomware attacks were responsible for causing the software failure incidents in New Mexico's most populous county, affecting the Albuquerque public school system and the computer systems of Bernalillo County [Article 123219].
Impacted Organization 1. Albuquerque public school system [Article 123219] 2. Bernalillo County, home to Albuquerque [Article 123219]
Software Causes 1. Ransomware attacks targeted the computer systems of Albuquerque's public school system and Bernalillo County, leading to system compromises and closures [Article 123219]. 2. The ransomware incidents disrupted various operations, including impacting teaching, learning, student safety, administrative functions, and public services like filing mortgages [Article 123219]. 3. The ransomware attacks caused issues with computer systems used for attendance, parent communication, and grade-keeping in the public school system [Article 123219]. 4. The ransomware attack on Bernalillo County affected the Metropolitan Detention Center, leading to temporary lockdowns, suspension of visitor access, malfunctioning automatic doors, and disruption of inmate incident report recording [Article 123219].
Non-software Causes 1. The cyberattacks were caused by ransomware, a form of hacking, which compromised systems in the Albuquerque public school system and Bernalillo County [Article 123219].
Impacts 1. The cyberattacks in New Mexico's most populous county disrupted public services, leading to the closure of the Albuquerque public school system and knocking out cameras at a local jail [Article 123219]. 2. The ransomware attack compromised systems that could impact teaching, learning, and student safety in the public school system, leading to the closure of schools [Article 123219]. 3. The ransomware attack on Bernalillo County's computer systems kept most administrative buildings closed to the public, affecting services such as filing mortgages [Article 123219]. 4. The ransomware incident in Bernalillo County forced the county jail to temporarily go into lockdown, suspend visitor access, and impact the functionality of automatic doors and inmate incident report database [Article 123219].
Preventions 1. Implementing robust cybersecurity measures such as regular security audits, penetration testing, and employee training to prevent cyberattacks like ransomware [123219]. 2. Ensuring timely software updates and patches to address known vulnerabilities that could be exploited by hackers [123219]. 3. Creating and regularly testing disaster recovery and incident response plans to minimize the impact of cyber incidents on critical systems and services [123219].
Fixes 1. Enhancing cybersecurity measures and protocols within the affected organizations to prevent future cyberattacks [123219] 2. Implementing regular software updates and patches to address vulnerabilities that could be exploited by hackers [123219] 3. Conducting thorough investigations to identify the root cause of the cyberattacks and taking necessary actions to mitigate risks [123219]
References 1. Albuquerque public school system 2. Bernalillo County 3. FBI's Albuquerque office 4. New Mexico Association of Realtors 5. Monica Armenta 6. Ellen Bernstein 7. Metropolitan Detention Center 8. Tia Bland

Software Taxonomy of Faults

Category Option Rationale
Recurring one_organization, multiple_organization (a) The software failure incident having happened again at one_organization: The article reports that the Albuquerque public school system experienced a cyberattack that compromised systems impacting teaching, learning, and student safety, leading to the closure of schools [123219]. This incident is a recurrence of a software failure within the same organization, the Albuquerque public school system. (b) The software failure incident having happened again at multiple_organization: The article mentions that ransomware attacks have plagued state and local governments for years, with a specific example of a 2019 attack on the city of Baltimore [123219]. This indicates that similar incidents have occurred at multiple organizations, affecting government entities beyond just Albuquerque.
Phase (Design/Operation) design, operation (a) The software failure incident related to the design phase can be seen in the ransomware attacks that disrupted public services in New Mexico's most populous county. The cyberattacks compromised systems that impacted teaching, learning, and student safety in the Albuquerque public school system, leading to the closure of schools [123219]. (b) The software failure incident related to the operation phase is evident in the ransomware attack on Bernalillo County, which resulted in most administrative buildings being closed to the public. Residents couldn't file mortgages due to the ransomware attack, highlighting the operational impact on public services [123219].
Boundary (Internal/External) within_system, outside_system (a) within_system: The software failure incident in Albuquerque, New Mexico, involved ransomware attacks that compromised computer systems within the public school system and Bernalillo County [123219]. These attacks impacted teaching, learning, student safety, and administrative functions, leading to the closure of schools and administrative buildings. The incident disrupted various internal processes such as taking attendance, contacting parents, and keeping grades within the affected systems. (b) outside_system: The ransomware attacks on the public school system and Bernalillo County were initiated externally by cybercriminals. The attacks were described as cyberattacks that disrupted public services in the county, affecting the Albuquerque public school system and the local jail's camera systems [123219]. The origin and responsibility for the separate hacking incidents were unclear, and the FBI was investigating the incidents.
Nature (Human/Non-human) non-human_actions (a) The software failure incident occurring due to non-human actions: The software failure incidents in New Mexico, including the cyberattacks on the Albuquerque public school system and the ransomware attack on Bernalillo County, were attributed to non-human actions such as cyberattacks and ransomware. These incidents disrupted public services, compromised computer systems, and impacted teaching, learning, student safety, and administrative operations without direct human participation in causing the failures [123219]. (b) The software failure incident occurring due to human actions: The articles do not provide specific information about the software failure incidents being directly caused by human actions. The focus is primarily on cyberattacks, ransomware, and the impact on public services and operations in New Mexico [123219].
Dimension (Hardware/Software) software (a) The software failure incidents reported in the articles are primarily related to software issues rather than hardware issues. The incidents involve cyberattacks, specifically ransomware attacks, that compromised computer systems in the Albuquerque public school system and Bernalillo County [123219]. These cyberattacks disrupted public services, impacted teaching, learning, student safety, and administrative operations, leading to closures of schools and administrative buildings. The ransomware attacks affected systems used for attendance, parent communication, grading, and even led to the suspension of visitor access at the county jail due to non-functioning cameras and technology [123219]. The incidents highlight the vulnerabilities in software systems to cyber threats rather than hardware failures.
Objective (Malicious/Non-malicious) malicious (a) The software failure incident in New Mexico, specifically affecting the Albuquerque public school system and Bernalillo County, was malicious in nature. The incidents were a result of cyberattacks, including ransomware attacks, which disrupted public services and compromised systems. The attacks were intentional and aimed at causing harm to the systems and the affected organizations [123219]. The FBI's Albuquerque office also acknowledged the seriousness of the cybercrime incidents, indicating the malicious nature of the attacks. (b) There is no information in the articles to suggest that the software failure incidents were non-malicious. The incidents were clearly attributed to cyberattacks and ransomware, indicating malicious intent behind the disruptions [123219].
Intent (Poor/Accidental Decisions) poor_decisions, accidental_decisions (a) The software failure incident in Bernalillo County and Albuquerque's public school system was due to poor decisions made by cybercriminals who carried out ransomware attacks. These attacks disrupted public services, compromised computer systems, and led to the closure of schools and administrative buildings. The incidents caused significant disruptions and financial losses, highlighting the toll that ransomware attacks can take on American life [123219]. (b) The software failure incidents were also a result of accidental decisions or mistakes made by the cybercriminals who initiated the ransomware attacks. The specific type of ransomware used in the attacks was not disclosed, and investigations were ongoing to determine the extent of the impact and the responsible parties. The incidents caused anxiety and uncertainty among the affected organizations and communities, emphasizing the challenges faced by state and local governments in dealing with cybersecurity threats [123219].
Capability (Incompetence/Accidental) development_incompetence (a) The software failure incident related to development incompetence is evident in the ransomware attacks that disrupted public services in New Mexico's most populous county. The cyberattacks compromised systems impacting teaching, learning, and student safety in Albuquerque's public school system, leading to the closure of schools [123219]. This incident highlights the toll that ransomware and hacking can take on American life, showcasing the potential consequences of inadequate cybersecurity measures or vulnerabilities in the systems developed by the organization responsible for the affected services. (b) The accidental software failure incident is demonstrated by the ransomware attack that infected the computer systems of Bernalillo County, leading to the closure of most administrative buildings to the public. This accidental incident resulted in residents being unable to file mortgages due to the ransomware attack [123219]. The unintentional nature of this failure is evident in the unexpected consequences of the cyberattack on the county's operations, disrupting services and causing inconvenience to the public.
Duration temporary The software failure incident reported in the articles can be categorized as a temporary failure. The ransomware attacks that disrupted public services in New Mexico's most populous county, including the Albuquerque public school system and the Bernalillo County administrative buildings, caused temporary disruptions. The Albuquerque public school system closed for a few days due to compromised systems impacting teaching, learning, and student safety [Article 123219]. Similarly, the Bernalillo County administrative buildings were closed to the public due to ransomware, affecting services like filing mortgages [Article 123219]. The Metropolitan Detention Center in Bernalillo County also faced temporary issues such as the temporary lockdown, suspension of visitor access, and malfunctioning technology like cameras and automatic doors [Article 123219].
Behaviour crash (a) crash: The software failure incident in Bernalillo County resulted in the jail's automatic doors being temporarily out of order due to the hack, impacting the facility's operations [Article 123219]. (b) omission: The ransomware attack on Albuquerque's public school system compromised some systems that could impact teaching, learning, and student safety, leading to the closure of schools [Article 123219]. (c) timing: The ransomware attack on Bernalillo County affected the jail's technology, causing a delay in the functioning of the cameras and other systems, leading to the suspension of visitor access and temporary lockdown [Article 123219]. (d) value: The ransomware attack on Bernalillo County disrupted the county's administrative operations, with most buildings closed to the public, affecting services like filing mortgages [Article 123219]. (e) byzantine: The separate cyberattacks on Albuquerque's public school system and Bernalillo County resulted in disruptions to various systems, leading to inconsistent responses and interactions within the affected organizations [Article 123219]. (f) other: The software failure incident in Albuquerque's public school system and Bernalillo County led to significant disruptions in various operations, impacting teaching, learning, administrative functions, and public services, showcasing the broader implications of cyberattacks on critical infrastructure and services [Article 123219].

IoT System Layer

Layer Option Rationale
Perception None None
Communication None None
Application None None

Other Details

Category Option Rationale
Consequence property, delay, non-human, theoretical_consequence (a) death: There is no mention of any deaths resulting from the software failure incident reported in the articles [Article 123219]. (b) harm: The articles do not mention any physical harm to individuals resulting from the software failure incident [Article 123219]. (c) basic: The incident did not impact people's access to food or shelter [Article 123219]. (d) property: The software failure incident impacted people's ability to file mortgages in Bernalillo County due to the ransomware attack [Article 123219]. (e) delay: The software failure incident led to the closure of Albuquerque's public school system, causing a delay in teaching and learning activities [Article 123219]. (f) non-human: The software failure incident affected the cameras at a local jail in Bernalillo County, impacting the jail's operations [Article 123219]. (g) no_consequence: There were real observed consequences of the software failure incident, including the closure of public schools, administrative buildings, and the temporary lockdown of the county jail [Article 123219]. (h) theoretical_consequence: The articles discuss potential consequences of ransomware attacks on state and local governments, such as financial costs and disruptions to services, which were not directly observed in this specific incident [Article 123219]. (i) other: The articles do not mention any other specific consequences of the software failure incident beyond those already discussed [Article 123219].
Domain knowledge (a) The failed system in the incident was related to the education industry, specifically impacting the Albuquerque public school system in New Mexico [Article 123219].

Sources

Back to List