Educational & easy-to consume visual guides to understanding attacks & enhancing resilience
In May 2024, the American Radio Relay League (ARRL), a prominent organisation in the amateur radio community, experienced a sophisticated ransomware attack that significantly disrupted its operations. The cybercriminals infiltrated ARRL's network, compromising various systems and both Windows and Linux servers. This breach led to the encryption of critical data, rendering essential services like the Logbook of The World (LoTW) inaccessible to users. The Federal Bureau of Investigation (FBI) categorised the attack as "unique," highlighting its advanced nature and the extensive impact on ARRL's infrastructure.
Faced with exorbitant ransom demands, ARRL engaged in negotiations with the attackers and ultimately agreed to pay a $1 million ransom to obtain the necessary decryption tools for system restoration. This decision, the organisation said, was made after careful consideration, aiming to expedite the recovery process and minimise prolonged service disruptions. Yet, throughout this challenging period, ARRL maintained transparent communication with its members, providing regular updates on the status of affected services and the ongoing recovery efforts.
Find out everything that happened in this ransomware attack in our ARRL Cyber Attack Timeline Documents.
Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.