Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Training topic

No spam. Unsubscribe anytime.

CISA adviser briefs Mobile County staff on ransomware, AI phishing and urges multi‑factor authentication

2112402 · January 15, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Clyde Rourke, a cybersecurity adviser with the Cybersecurity and Infrastructure Security Agency and a cryptologic warfare officer in the Navy Reserve, told Mobile County staff during a training session that local governments are “very juicy target[s]” for nation‑state actors and organized ransomware gangs and described practical steps employees can take to reduce risk.

Clyde Rourke, a cybersecurity adviser with the Cybersecurity and Infrastructure Security Agency (CISA) and a cryptologic warfare officer in the Navy Reserve, told Mobile County staff during a training session that local governments are “very juicy target[s]” for nation‑state actors and organized ransomware gangs and described practical steps employees can take to reduce risk.

Rourke opened by showing a CISA video explaining the agency’s mission and noted: “In a globally interconnected world with interdependent infrastructure, threats to one are a threat to all.” He told attendees CISA supports federal, state, local, tribal and territorial partners with information, tools and training to protect critical infrastructure such as water, wastewater and the electrical grid.

Why it matters: Rourke said smaller local governments are attractive targets because a successful attack generates news coverage and public alarm. He cited recent shifts in ransom demands and methods — including greater use of artificial intelligence to craft highly targeted phishing messages — and said the effects of a cyberattack can mimic those of a natural disaster by knocking out services such as power, water or 9‑1‑1.

Details of the threats: Rourke described three broad threat groups: nation‑state actors (he named China, Russia, North Korea and Iran), organized ransomware groups and insider threats. He said organized ransomware operations now resemble businesses with structure and resources, and that adversaries increasingly use AI to scrape social media and public sources to create convincing, urgent emails that prompt a single click to compromise networks. “The adversary is using artificial intelligence to generate these emails and these invoices,” he said.

Rourke gave multiple numerical examples attendees could use to gauge scale: he said the average ransom in 2019 was about $115,000, that recent averages have risen to roughly $2,730,000, and that the highest reported ransom last year reached $75,000,000. He also cited industry estimates that wire‑transfer fraud and related losses totaled roughly $55,000,000,000 between 2013 and 2023 and said the City of Lexington lost about $1,200,000 to invoice‑change fraud over several months. He referenced the City of Oakland’s 2023 ransomware incident as an example of downstream legal and operational consequences.

Artificial intelligence, deepfakes and social media: Rourke warned that AI makes phishing and extortion more effective by producing realistic emails, invoices and voice or video deepfakes. He described an example in which voice cloning produced a fraudulent kidnapping call that nearly led to a family wiring money. He also told federal employees they are barred from using TikTok and said the platform is “an intelligence gathering platform for China,” attributing that claim to the training remarks. He cautioned staff to review social media settings and limit personal information that could be scraped to create targeted attacks.

Common attack vectors and examples: Business email compromise and invoice‑swap scams were highlighted as frequent causes of large losses. Rourke described typical schemes in which an attacker sends a vendor‑looking invoice with new bank details and the organization wires funds to the attacker’s account. He recommended calling the vendor or the bank — not a phone number in the suspicious email — to confirm changes.

Recommended protections and actions: Rourke emphasized two practical defenses he urged staff to adopt: employee training and multifactor authentication (MFA). “Multifactor authentication is the easiest way to thwart a cyber attack,” he said, explaining MFA as “something you know” (password) plus “something you have” (a phone that receives a one‑time code). He also advised staff not to store personal or sensitive photos and documents on work computers or servers because such material is commonly used for extortion once adversaries access networks.

Scope and follow up: Rourke said CISA can perform technical assessments, conduct penetration tests and provide outreach. He described his work conducting vulnerability assessments and public training sessions and directed attendees to CISA’s website for more resources. The presentation included a CISA video and question time; attendees asked few questions in this session.

Closing: Rourke closed by reiterating that training and basic controls can substantially reduce risk and said staff should contact their IT teams to enable MFA and confirm procedures for handling suspicious emails and vendor payment changes. He recommended visiting cisa.gov for additional guidance.