Claim details
Devman claimed the authority and data theft; the authority confirmed a ransom demand but not Devman attribution or stolen data.
The Georgia Superior Court Clerks’ Cooperative Authority detected network access by an intruder Nov. 21, 2025, and restricted websites and applications while stopping an attempted ransomware attack before encryption. Electronic records and filings were disrupted statewide; the authority said systems returned to normal by Nov. 28.
Unauthorized access to systems, accounts, networks, or data.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
An authoritative source stated that no ransom or extortion payment was made.
In a Nov. 28 statement, the Georgia Superior Court Clerks’ Cooperative Authority said its team detected anomalous network activity Nov. 21 and found an intruder had reached the network perimeter. It said it interrupted a ransomware attack before encryption, destruction or alteration of data. This confirms an intrusion and attempted ransomware, but it should not be described as successful encryption. Our Nov. 25 report covered the service disruption while investigators were still responding.
The authority restricted access to websites, applications and statewide records resources while it inspected more than 100 servers and workstations. County clerks reported that electronic real estate filings, notary applications, UCC filings and certifications were unavailable, leading some offices to accept paper filings. The statewide area link reflects the authority’s service remit, while Atlanta is its physical office anchor; it does not mean every county office was compromised.
The authority said it received a ransom demand accompanied by claims of stolen data and encryption, but did not engage and paid nothing. It said an attacker-supplied screenshot likely showed a development server with test data, and its investigation had not confirmed any stolen data or access to sensitive nonpublic information. Devman’s leak-site claim is recorded as an allegation, not confirmed attribution or data theft.
The authority said the threat was neutralized and all its systems had returned to normal operation by Nov. 28. The incident is therefore resolved as to the reported operational outage, although forensic analysis of the data claim continued.
Confidence is high in the intrusion attempt, defensive service shutdown and restoration because the authority detailed each. Devman’s responsibility and its data-theft claims remain unverified. Initial access, precise attacker dwell time and any exfiltration were not established in the reviewed sources.
Devman claimed the authority and data theft; the authority confirmed a ransom demand but not Devman attribution or stolen data.

Georgia’s statewide court records authority has taken its website and e-filing systems offline after detecting a ‘credible and ongoing cybersecurity threat,’ slowing real estate and notary transactions across multiple counties.
Because of the speed of our detection and response, the GSCCCA successfully interrupted a ransomware attack in progress before any encryption, destruction, or alteration of data occurred. At this time, the GSCCCA confirms that the threat has been fully neutralized and that all GSCCCA systems have been safely reverted to normal operation.
The contemporaneous DysruptionHub report linked a Devman leak-site listing that claimed the authority and alleged roughly 500 gigabytes of data theft. The authority disputed confirmed theft and said the supplied image likely showed a test database.
Signed-in members can report an error, update, or missing source.