Baltimore estimates recent ransomware attack will cost the city $10M to clean up, not including $8M of deferred or lost revenue from unprocessed payments
Data Sheet Tweets: Ian Duncan / @iduncan : City officials have said there's no evidence personal data was stolen by the hackers. But a spokesman for the mayor says authorities are investigating documents posted to the Twitter account https://www.baltimoresun.com/ ... Ian Duncan / @iduncan : I asked a Twitter account claiming to be the Baltimore ransomware hackers to prove it. So they left a message on a dark web page they set up to talk to the city. Before it was shut down, the Twitter account threatened to leak city documents https://www.baltimoresun.com/ ... Peter Coffee / @petercoffee : City of Baltimore says “as many as 90 percent” of city employees are “getting back online by the end of the week” following May 7 ransomware attack. Their capability has been (literally) decimated (or worse) for a *month*. Wow. https://statescoop.com/... and https://www.merriam-webster.com/ ...
Context & Ripple Effects
Two weeks after the May 7 ransomware attack left Baltimore's utilities billing, phone, and email systems offline, the city has put a first price tag on the damage: $10M in cleanup costs on top of $8M in deferred or lost revenue from unprocessed payments. Officials say there is no evidence personal data was stolen, but investigators are probing documents posted to a Twitter account linked to the hackers, who threatened to leak city files via a dark web page before it was shut down.
First-order effects
- Baltimore joins Atlanta as a US city paying far more to refuse a ransom than the demand itself — Atlanta spent roughly $2.6M recovering from its 2018 attack against a ~$50,000 ransom request, and Baltimore's $18M combined figure sets a new local-government benchmark for refusal costs.
Second-order effects
- The leak threat adds a new pressure vector beyond encryption: even cities that refuse to pay face extortion over stolen documents, pushing municipal buyers toward insurers and vendors who can price both downtime and data exposure.
Third-order effects
- With attackers later shifting toward managed service providers to hit many city governments at once, per-incident cleanup bills like Baltimore's are likely to harden into standing budget lines — cyber insurance requirements, offline backups, and dedicated recovery funds become baseline municipal infrastructure rather than optional spending.
The trend: Ransomware is becoming a recurring, priced-in operating cost for US city governments, with each high-profile refusal like Baltimore's recalibrating what municipalities budget for resilience.