A California city whose police department recently revealed it was hacked has now acknowledged it suffered another attack in 2018.The 63-officer Azusa was targeted by the DoppelPaymer ransomware gang in late winter. The attack was kept secretwhile officials worked with the FBI, the Los Angeles County Sheriff’s Department and ransomware consultants to recover hundreds of highly sensitive files encrypted in the incident.
Read also: Massachusetts: Steamship Authority victim of ransomware attack
In April, a trove of department documents was leaked online after the city chose not to pay the ransom demanded by the gang. The leaked information included criminal records and payroll records, which contained Social Security numbers, driver's license numbers, medical information and financial account information.

The city finally publicly acknowledged the hacking attack on May 27, which coincided with the start of Memorial Day, when America typically steps away from the news feed and honors the fallen.
See also: FBI links JBS ransomware attack to REvil gang
The Azusa Police Department issued a "data security breach notification" stating that it had been hit by a "sophisticated ransomware attack" and that "certain Azusa Police Department information was obtained by an unauthorized individual.".

Now the city has reported a ransomware attack by another anonymous cybercriminal organization in the fall of 2018. Azusa City Manager Sergio Gonzalez said insurance company Chubb paid $65,000 to regain control of 10 data servers at the police department that were taken over by hackers for more than a week.
“We were able to unlock one server after paying the ransom, but we soon found a free key to unlock all the other locked servers. No information was compromised. Our servers were just locked,” Gonzalez said in an email.
Suggestion: Another American city victim of ransomware attack

Gonzalez also added that the 2018 attack had not been reported because an investigation had proven that no data had been exposed during the incident.
Specifically, Gonzalez pointed out the following: "We confirmed with forensic experts that no data has been compromised. This is why we judged that it was not necessary to report the incident (publicly)."
The Whittier Daily News reports that the 2018 attack took place when a city employee opened an email and clicked on a malicious link.
Information source: info-securitymagazine.com
