Atlanta government ransomware attack
massive ransomware attack against the government of the City of Atlanta

The city of Atlanta, Georgia was the subject of a ransomware attack which began in March 2018. The city recognized the attack on Thursday, March 22, 2018, and publicly acknowledged it was a ransomware attack.
Due to Atlanta's national importance as a transportation and economic hub, the attack received wide attention and was notable for both the extent and duration of the service outages caused. Many city services and programs were affected by the attack, including utility, parking, and court services. City officials were forced to complete paper forms by hand.
On November 26, 2018, a grand jury indicted two Iranian security hackers, Faramarz Shahi Savandi and Mohammad Mehdi Shah Mansouri, for the attack. The Department of Justice alleged that Savandi and Mansouri are part of the SamSam group; that the SamSam group is based out of Iran; and that the pair created SamSam Ransomware, the malware used in the attack. There are no affiliations with the government of Iran.
Approach and attack
Leading up to the attack, the Atlanta government was criticized for a lack of spending on upgrading its IT infrastructure, leaving multiple vulnerabilities open to attack. In fact, a January 2018 audit found 1,500 to 2,000 vulnerabilities in the city's systems, and suggested that the number of vulnerabilities had grown so large that workers grew complacent.
The public source identifies “Atlanta government ransomware attack” as massive ransomware attack against the government of the City of Atlanta. This brief keeps that definition visible, then builds a research path around Atlanta, government and ransomware.
Why this record matters
A short description can identify a subject without explaining its stakes. For “Atlanta government ransomware attack”, the useful work is to connect “massive ransomware attack against the government of the City of Atlanta” to the records capable of establishing context and consequence.
Maps, plans, fabric surveys and administrative records can establish how the site’s name, extent and function changed over time. The source revision retrieved here is dated Jun 21, 2026. The linked authority identifier is Q55075376. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2018.
Architectural summaries often privilege surviving fabric and can understate demolished phases, contested use or displaced communities. The lead is largely declarative, so disagreement and counter-evidence require a deliberate search beyond the opening account. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Treat names, boundaries and functions as historically changeable. Maps, plans, inventories and administrative records can clarify what the place meant at different dates.
- Historic place names
- Jurisdictional context
- Routes into maps and plans
Contemporary maps, plans, listed-building records, estate papers and the responsible local or national archive.
Three-step research path
- Establish the record: confirm the title “Atlanta government ransomware attack”, its source revision and the description used here.
- Expand the search: follow Atlanta government ransomware attack primary sources, Atlanta government ransomware attack archive and Atlanta research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “Atlanta government ransomware attack”?
- Which earlier names or jurisdictions may reveal additional records?
- What physical evidence or contemporary plan supports the description?
Search terms from this dossier
This entry incorporates text from “Atlanta government ransomware attack” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.