lockbit3 attacks town of stmarys

Incident Date:

July 22, 2022

World map



lockbit3 attacks town of stmarys


town of stmarys




St. Marys, Canada

Ontario, Canada

First Reported

July 22, 2022

St. Marys, Ontario, Suffers Ransomware Attack by LockBit 3.0

Impact and Response

The small town of St. Marys, Ontario, became a target of the infamous LockBit 3.0 ransomware group, leading to a significant cybersecurity breach that incurred over $1.3 million in management costs. This incident, which took place on July 20, 2022, was identified amidst a routine system backup by the town's IT personnel.

In response to the attack, which encrypted files and servers, the town acted swiftly to mitigate further damage. Key municipal services, including transit and water systems, remained operational, preserving approximately 80% of town functionality. To navigate through the incident, St. Marys enlisted Deloitte for technical leadership and forensic auditing, alongside Siskinds LLP for incident response direction.

Cost and Recovery

The financial toll of the incident encompassed $860,970 allocated for incident management and investigation, alongside a ransom payment close to $300,000 in Bitcoin to secure decryption keys. Additionally, $440,133 was directed towards reconstructing the town's IT network, a project completed by Deloitte and subsequently transitioned to the town in November 2022.

Vulnerabilities and Prevention

The LockBit 3.0 attack underscores the critical need for stringent cybersecurity defenses, especially within the government sector. Despite St. Marys' initiative to migrate its operating environment to the cloud in 2020—a move that safeguarded critical services—the town still fell prey to the ransomware group. Cybersecurity specialists advocate for preemptive strategies, including regular security evaluations, employee training, and the engagement of third-party monitoring services to deter and diminish the impact of cyber threats.

The ransomware assault on St. Marys underscores the persistent menace posed by cybercriminals and the imperative of comprehensive cybersecurity protocols. Despite the substantial financial and operational upheaval inflicted by the attack, the town managed to recuperate and reinstate its systems, thanks to professional intervention.


Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.