Skip to content

Georgia Superior Court Clerks' Cooperative Authority Intrusion

Summary

Georgia Superior Court Clerks' Cooperative Authority logo

The Georgia Superior Court Clerks’ Cooperative Authority detected network access by an intruder Nov. 21, 2025, and restricted websites and applications while stopping an attempted ransomware attack before encryption. Electronic records and filings were disrupted statewide; the authority said systems returned to normal by Nov. 28.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Impacted locations

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Payment denied

    An authoritative source stated that no ransom or extortion payment was made.

Incident narrative

Analyst assessment

In a Nov. 28 statement, the Georgia Superior Court Clerks’ Cooperative Authority said its team detected anomalous network activity Nov. 21 and found an intruder had reached the network perimeter. It said it interrupted a ransomware attack before encryption, destruction or alteration of data. This confirms an intrusion and attempted ransomware, but it should not be described as successful encryption. Our Nov. 25 report covered the service disruption while investigators were still responding.

Operational significance

The authority restricted access to websites, applications and statewide records resources while it inspected more than 100 servers and workstations. County clerks reported that electronic real estate filings, notary applications, UCC filings and certifications were unavailable, leading some offices to accept paper filings. The statewide area link reflects the authority’s service remit, while Atlanta is its physical office anchor; it does not mean every county office was compromised.

Extortion and data claims

The authority said it received a ransom demand accompanied by claims of stolen data and encryption, but did not engage and paid nothing. It said an attacker-supplied screenshot likely showed a development server with test data, and its investigation had not confirmed any stolen data or access to sensitive nonpublic information. Devman’s leak-site claim is recorded as an allegation, not confirmed attribution or data theft.

Current status

The authority said the threat was neutralized and all its systems had returned to normal operation by Nov. 28. The incident is therefore resolved as to the reported operational outage, although forensic analysis of the data claim continued.

Confidence and uncertainty

Confidence is high in the intrusion attempt, defensive service shutdown and restoration because the authority detailed each. Devman’s responsibility and its data-theft claims remain unverified. Initial access, precise attacker dwell time and any exfiltration were not established in the reviewed sources.

Threat actor and claim

Listed as: Georgia Superior Court Clerks' Cooperative AuthoritySource: ransomware.livePublished:

Claim details

Devman claimed the authority and data theft; the authority confirmed a ransom demand but not Devman attribution or stolen data.

Organizations involved

Impacted locations

Sources

Cyber threat at Georgia court records hub disrupts filings

Georgia’s statewide court records authority has taken its website and e-filing systems offline after detecting a ‘credible and ongoing cybersecurity threat,’ slowing real estate and notary transactions across multiple counties.

Statement on Recent Outage

Because of the speed of our detection and response, the GSCCCA successfully interrupted a ransomware attack in progress before any encryption, destruction, or alteration of data occurred. At this time, the GSCCCA confirms that the threat has been fully neutralized and that all GSCCCA systems have been safely reverted to normal operation.

Devman claim naming GSCCCA

The contemporaneous DysruptionHub report linked a Devman leak-site listing that claimed the authority and alleged roughly 500 gigabytes of data theft. The authority disputed confirmed theft and said the supplied image likely showed a test database.

See something that needs correction?

Signed-in members can report an error, update, or missing source.