The FBI’s warning describes a route into U.S. organizations, including local governments: Iran-based cyber actors build or obtain network access, then work with ransomware affiliates. For cities and counties, the practical response is to tighten access and remote connections, limit how far an intruder can move, prepare recoverable backups, and know how to report a suspected incident.
What the FBI warning says
A joint FBI, CISA, and DC3 advisory dated August 28, 2024 says Iran-based cyber actors were exploiting U.S. organizations, including local government entities, to obtain and develop network access and then collaborate with ransomware affiliates. The advisory lists the actors under several names: Pioneer Kitten, Fox Kitten, UNC757, Parisite, RUBIDIUM, and Lemon Sandstorm. It says they worked with affiliates associated with NoEscape, Ransomhouse, and ALPHV. Read the FBI advisory.
The warning is about both the initial foothold and what can follow. A successful intrusion can give attackers access to systems and data; ransomware affiliates may then encrypt systems and threaten to publish stolen information. The advisory does not say every local government has been targeted, nor does it identify a count of affected municipalities.
Why local governments are at risk
Municipal networks support many departments and services, so an intrusion that starts with one account or exposed system can become a broader operational problem if access is not contained. The FBI’s broader 2023 context was that investigators were handling more than 100 ransomware variants, each with scores of victims, affecting sectors that included emergency services and state and local governments. That figure was FBI Deputy Director Paul Abbate’s statement in 2023, not a current count of active variants or a measure of local-government incidents. Read Abbate’s remarks.
Recommended Free Tools
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
More recent federal advisories show the scale of ransomware activity beyond the specific 2024 warning, but their figures cover different scopes and should not be treated as municipal victim counts:
| Figure | Scope and date | What it does—and does not—show |
|---|---|---|
| More than 300 victims | Medusa ransomware victims by February 2025; FBI, CISA, and MS-ISAC advisory published March 12, 2025. | A count associated with Medusa, not a count of local governments. Medusa advisory. |
| Approximately 900 affected entities | Play ransomware, as of May 2025; FBI, CISA, and ASD ACSC update published June 4, 2025. | An estimate of entities affected by Play, not a count limited to municipalities. Play advisory. |
| More than 3,600 complaints and losses exceeding $32 million | FBI Internet Crime Complaint Center ransomware figures for 2025. | Reported complaints and losses across the reporting population, not a local-government total. IC3 cautions that reports are incomplete and losses omit many indirect costs. 2025 IC3 report. |
How attackers can get into municipal networks
The Play advisory describes several routes attackers may use. These include abused valid accounts; vulnerable public-facing applications; vulnerabilities in FortiOS and Microsoft Exchange; remote desktop protocol (RDP) and virtual private network (VPN) access; and a vulnerability in SimpleHelp identified in 2025. The advisory also describes network discovery, disabling security tools, lateral movement, data theft, and encryption. These are Play activity findings, not a claim that every group named in the 2024 warning used every listed method.
Medusa is described as a ransomware-as-a-service operation: affiliates use the service to carry out attacks. Its advisory, like Play’s, describes double extortion—stealing data before encryption and threatening to release it. The Medusa advisory recommends timely patching, network segmentation, and filtering untrusted origins from internal remote services.
What a city or county should do
Use the warning as a prompt to check whether the basics are both in place and working. Start with the paths that could expose an account or remote service, then reduce the damage an intruder could cause and verify that recovery is possible.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #3
- INTEGRATED FIREWALL APPLIANCE AND SECURITY SERVICES: Comes with FortiGate-40F Firewall Appliance, 1 year of FortiCare Premium, and FortiGuard Unified Threat Protection.
- UTP SECURITY FEATURES: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
- IDEAL FOR SMALLER SETTINGS: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
- CONTINUOUS SUPPORT AND MAINTENANCE: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
- COMPACT AND EFFECTIVE: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.
- Patch exposed systems promptly. Keep operating systems, applications, and firmware current, and prioritize known exploited vulnerabilities. Include public-facing systems and remote-access infrastructure in the review.
- Strengthen account access. Require multifactor authentication (MFA), prioritizing webmail, VPN, privileged accounts, and accounts used to manage critical systems. Review valid accounts and remove access that is no longer needed.
- Limit remote connections. Restrict RDP and other remote services to approved users and necessary origins. Filter connections from unknown or untrusted origins rather than exposing internal remote services broadly.
- Segment the network. Separate departments and critical systems where practical, and restrict traffic between segments. Segmentation can make it harder for an attacker with one foothold to move across the organization.
- Protect backups from the network. Maintain encrypted, offline, or immutable backups that cover the organization’s data infrastructure. A backup that an intruder can alter or encrypt along with production systems may not support recovery.
- Test restoration and response. Keep a recovery plan and exercise restoring systems and data. Test security controls against relevant MITRE ATT&CK techniques so the organization can identify gaps before an incident.
- Prepare reporting contacts. Make sure staff know how to contact a local FBI field office, the FBI’s Internet Crime Complaint Center (IC3), CISA, and—where applicable to state, local, tribal, and territorial (SLTT) organizations—MS-ISAC. The Medusa and Play advisories provide incident-reporting guidance and contacts.
What to do if ransomware is suspected
Follow the organization’s incident-response and continuity plans rather than improvising decisions in the middle of an outage. Bring together the people responsible for IT and security, service continuity, and leadership, and use the prepared FBI, CISA, IC3, and MS-ISAC reporting channels. The advisories describe both encryption and theft, so responders should consider the possibility that data was accessed or exfiltrated, not only that systems are unavailable. Keep the incident and recovery decisions coordinated across affected departments.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Should a local government pay the ransom?
The FBI discourages paying. Payment does not guarantee that the organization will regain access to its data, does not ensure stolen information will stay private, and can incentivize further attacks. Play’s documented double-extortion approach illustrates why decryption alone may not resolve the risk: attackers can also demand payment under threat of publishing exfiltrated information. The federal advisories document cryptocurrency demands, but they do not establish that paying is a reliable path to recovery.
Quick Recap
Rank #4
- SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
- Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
- Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
- Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
- Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

