Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Anne Arundel officials describe year‑long cyber incident, data‑mining and notification plans

Anne Arundel County Council · July 15, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

County IT and security staff briefed the council on a January intrusion that led to data deletion attempts on Feb. 22, forensic analysis, and ongoing data‑mining to identify affected records; officials said the incident was ‘closed’ on April 9 and that notification work could finish by September.

County Chief Administrative Officer Christine Anderson introduced a multi‑agency briefing on a cybersecurity incident that began with unauthorized access to a county VPN account and resulted in a forensic investigation, system rebuilds and a prolonged data‑mining effort to identify potentially impacted records.

Donnie Green, the county’s chief information security officer, outlined the incident timeline. He said threat actors gained access on Jan. 28 via a compromised account and that on Feb. 22 attackers attempted to execute ransomware but were blocked by endpoint detection; attackers then deleted data on some drives. Green said county teams engaged law enforcement, CISA and the FBI, activated the incident response plan and brought in cyber‑liability insurance and forensic vendors.

County staff reported the incident was declared over on April 9 after forensic work. Presenters said forensic analysis found data exfiltrated from the network and that a third‑party data‑mining vendor (engaged by the insurance carrier) is narrowing a starting set of more than 1,000,000 data points to determine who must be notified. The county told the council it has coordinated with Health and Human Services and the Office for Civil Rights because the scope likely includes protected health information.

A county staff member said the team expects the affected population could exceed 150,000 people and is preparing notices and substitute notice under Maryland law; HIPAA‑required individual notice will be provided for protected health information once contact information is verified.

Jack Martin, director of IT, described the recovery steps: an inventory‑based approach prioritized systems by public safety and finance, systems were rebuilt and reviewed by internal and external security experts, the VPN was rebuilt with certificate and MFA requirements, remote desktop protocol access was removed, micro‑segmentation was introduced and single sign‑on and MFA rollouts are being expanded to desktops. Martin estimated a phased MFA rollout to all desktops in about three to four months.

Councilmembers asked whether historical records were irretrievably lost (staff said backups restored ‘‘almost everything’’), why the data‑mining and notification process took over a year (vendors and scale of data cited), and whether cloud vendors bear responsibility (presenters described shared responsibility models and vendor cooperation in recovery). The administration committed to update the council when the final notification list is complete and to provide the council with a count of people to be notified.

No formal action was taken; the briefing closed with the council requesting follow‑up on final notification timing and confirmation of restoration completeness.