How One Bad Click Shut Down Fulton County

In January 2024, everyday life in Fulton County came to a standstill. Residents couldn’t register their vehicles, pay their utility bills, obtain marriage licenses, or even call county offices because the phone system was down. Everything ground to a halt because one employee clicked a malicious link. In most cases, the damage would have been limited, but this employee had administrative privileges, giving the attackers access to far more than a single computer.

Most employees only need access to the systems required to do their jobs. Administrative privileges are like having a master key to the building instead of just a key to your office. And when someone with access to everything makes a mistake, it doesn’t stay in their corner of the network. It becomes everyone’s problem, and that’s exactly what happened in Fulton County.

Within hours, a Russian ransomware syndicate named LockBit worked through the county’s network from that entry point. The court system went offline. The phones went dark. Tax systems, jail systems, and a long list of critical services ground to a halt.

Many systems took weeks to recover, all while residents tried to conduct the everyday business that society runs on. The recovery cost didn’t end up being the biggest blow, nor did the enormous ransom demand or the exposure of sensitive data. The greatest cost was operational paralysis. When employees can’t work and customers can’t access services, every hour of downtime ripples through the system.

Two controls should have stopped this attack before it became a disaster:

  • Least Privilege Access: The employee who clicked that link shouldn’t have had elevated rights. When users access only what their job requires, one bad click stays small. Instead of handing an attacker the keys to the kingdom, where access confines them to a much smaller area of the networks, dramatically limiting what they can access or damage.
  • Managed Detection and Response (MDR): After LockBit gained that initial foothold, it didn’t immediately detonate the ransomware. They moved through the network, dumping credentials, hopping between systems, and quietly expanding their permissions. That movement leaves tracks that a properly managed detection tool watches for. It is exactly this kind of behavior it looks for so it can proactively shut down systems to stay ahead of the threat actors.

Neither of these requires a massive budget or a full security team. They are foundational controls that any organization can implement. One limits the damage when something goes wrong; the other makes sure you know something is wrong before it spirals. They are designed to work together to ensure a single mistake doesn’t become a business-wide crisis.

Are you prepared for the operational paralysis and uncertain recovery that follow a ransomware event? Don’t wait to find out how much access your users have by watching how far an attacker gets. Fulton County’s experience is a reminder that ransomware doesn’t have to begin with a sophisticated attack. Sometimes it starts with one click, and what happens next depends on how your network is configured. Network 1 Consulting can help you evaluate user permissions, strengthen detection capabilities, and identify vulnerabilities before they become costly disruptions, so the next time someone clicks the wrong thing, it stays a small problem.

If you’d like to assess where your organization stands, reach out to [email protected] to continue the conversation.

Security Team written over top of the Network1 logo.

Security Team: We monitor threats, strengthen defenses, deliver policies & training and help keep your business protected. With proactive support, expert guidance, and fast response times, we help prevent breaches before they happen and stop breaches if they do happen.

Network 1 designs, builds and supports the IT you need to run your business more securely, productively and successfully. Whether you want to outsource all of your IT needs to a reliable, responsive, service-oriented company, or need to supplement the work of your internal IT staff, we will carefully evaluate where you are now, discuss where you want to go and implement and support a plan to get you there with as little interruption as possible.

Related Posts