The City of Dallas Ransomware Attack and What a Local Business Does Next
What the City of Dallas ransomware attack cost, why it started with a stolen account, and what a North Texas business should do in the first hour after a compromise.
In May 2023 the City of Dallas found out that it had been robbed weeks earlier. The ransomware went off on a Wednesday, police dispatch fell back to radios and paper, municipal courts closed their doors, and the city spent the rest of the year counting what had left the building. It remains the most thoroughly documented cyber attack in North Texas, and it is worth rereading now for one reason. Almost everything the city learned the hard way applies to a forty-person company in McKinney, Plano or Frisco, and almost none of it is about buying better software.
This post walks through what happened in Dallas, what it cost, and what it means for a local owner who will never run a police department but does run a mailbox, a payroll system and a list of vendors who expect to be paid. It assumes the bad day has already arrived. Prevention matters, but the owners who call us are rarely calling about prevention. They are calling because something has already gone wrong, and the first few hours decide how expensive it becomes.
What Happened to the City of Dallas
Ransomware is software that scrambles a victim's files so they cannot be opened, paired with a demand for payment to unscramble them. Modern ransomware crews also copy the files out first, so that even a victim with good backups faces a second threat, which is that the stolen data will be published. The group that hit Dallas was called Royal, and it operated exactly this way.
The part most people missed in the headlines is the timeline. The city's own after-action reporting found that the attackers had been inside the network for weeks before anyone saw a ransom note, using a stolen account to move around and copy data. Security people call this period dwell time, which simply means the time an intruder spends inside your systems before you notice. By the time the encryption started, the theft was already finished. We explain why that gap is so common in our piece on how long an attacker hides in your network.
When the city did notice, it did what it had to do and pulled systems offline to stop the spread. That is the right call, and it is also why the public felt the attack. Computer-aided dispatch, the system that helps send police and fire units to calls, went to manual operation. Courts could not process cases. Library and permitting systems went dark. Residents could not pay certain bills online. None of that was the attackers breaking things one at a time. It was the cost of containment, meaning the deliberate act of disconnecting systems so the damage stops growing.
What It Cost and Who Ended Up Paying
The city later reported that personal information belonging to more than twenty-six thousand people had been exposed, and the city council approved roughly eight and a half million dollars in spending to respond and recover. That figure covers outside investigators, rebuilt systems, credit monitoring for the people affected, and staff time pulled away from normal work. It does not include the harder costs to measure, such as delayed court dates, delayed permits, and the months of follow-up work that a breach leaves behind.
Scale that down and the shape stays the same. A Collin County distributor with thirty employees does not have eight and a half million dollars of exposure, but it has the same categories of cost. It has days of downtime where orders cannot ship and invoices cannot go out. It has an outside digital forensics bill, which is the cost of a specialist reconstructing what the attacker touched so you know what you have to report. It has notification letters if employee or customer records were taken, possible regulatory questions, and a cyber insurance renewal that will ask, in writing, what happened and what you changed.
There is a second layer of cost that the Dallas story makes very clear, and it lands on people who were never attacked at all. Once stolen data exists, it gets used. The residents, employees and vendors whose details walked out of the city network became the raw material for the next round of fraud. That is the same pattern we described in what the JPS attack means for Fort Worth businesses, where the hospital was the headline and the vendors who invoiced it became the target. A breach at a large North Texas institution does not end when its systems come back. It moves outward to everyone connected to it.
The Lesson for a Local Owner Is About Accounts, Not Servers
Most owners hear "ransomware" and picture a hacker breaking through a firewall. That is rarely how it starts. In Dallas the foothold was an account, a username and password that worked. In the small and mid-size businesses we respond to across North Texas, it is almost always the same. An employee types their password into a convincing fake login page, an attacker signs into the real mailbox from somewhere else, and nobody notices because nothing looks broken.
What happens next depends on what the attacker wants. Some crews use the mailbox as a doorway into the rest of the network and eventually deploy ransomware. Many never bother. They stay in the mailbox, read weeks of conversation, learn who approves payments and how invoices are worded, and then send one message. Business email compromise, usually shortened to BEC, is the name for this. A criminal takes over a real business mailbox and uses it to redirect money, either by sending fake invoices to your customers or by tricking your own accounts payable team into paying a fake vendor.
This is the single most common way we see local businesses lose real money, and it is why the Dallas timeline matters so much. The attackers were inside for weeks before the city knew. In a mailbox takeover, the equivalent is the attacker reading your email for weeks before the fraudulent invoice goes out. If you discover it the day a customer calls to ask why your bank details changed, the theft of information is already complete, just as it was in Dallas. Your job at that point is not prevention. It is response.
What to Do in the First Hour After You Find a Compromise
The first hour is where a bad week becomes either a contained incident or a long one. The city's experience shows the core principle, which is that you stop the spread first and investigate second. For a small business that usually means three things happen quickly and in order.
First, cut off the attacker's access to the account. That means resetting the password, signing the account out of every device and session, and checking whether the attacker added a forwarding rule or a second way to log in. A forwarding rule is a setting that quietly copies incoming mail to an outside address, and attackers add one so they keep reading your email even after you change the password. Our guide to the first 48 hours after a compromised Microsoft 365 mailbox covers what to look for.
Second, if money has moved, call the bank before you call anyone else. Wire and ACH payments can sometimes be recalled, but only inside a short window, and the window closes while people are still arguing about whose fault it was. We walk through that call step by step in how North Texas businesses recover the money after a fake invoice. Speed matters far more than having every detail right.
Third, do not wipe anything. The instinct is to clean the infected laptop and move on, but that erases the evidence you will need later to answer your insurer, your customers and possibly a regulator. Preserve logs, keep the suspicious emails, and write down the times things happened. An experienced incident response team can then reconstruct what the attacker saw and sent, which is the only reliable way to know whether you have a notification obligation.
What to Tell Your Customers and Vendors This Week
Dallas had one advantage that a small company does not. Every news outlet in the region covered the attack, so its vendors and residents knew to be suspicious without being told. When a twenty-person firm in Allen or McKinney is compromised, nobody writes a story. The only version of events your customers will ever hear is the one you give them, and if you say nothing, the attacker's fake invoice is the last thing they received from you.
That is why customer notification belongs inside the incident, not after it. If your mailbox was used to send anything, the people who received those messages need a short, direct warning from a channel you trust, ideally a phone call from someone they already know. Tell them not to act on any payment instruction from your company until they confirm it by phone at a number they already have on file. Do not send that warning only by email from the same mailbox that was compromised. We cover the wording and the order of those calls in our post on what to tell clients after a fraudulent invoice leaves your mailbox.
The same discipline applies in the other direction. If a supplier, a hospital, a city office or any large organization you work with announces a breach, assume your contact details and payment history may be in the stolen data. For the next few months, treat any change to bank details from that relationship as suspicious until it is confirmed by phone. A dark web monitoring service can tell you when your own company's logins or records show up for sale, which often gives you a warning before the fraud attempt arrives. Our business email compromise service handles both sides of this, containing the mailbox and coordinating the outreach so that customers hear the truth before they pay the attacker.
What Dallas Teaches About Being Ready Before It Happens
The response steps above work best when they are decided in advance. The city had trained staff and an established technology department and still lost weeks to recovery. A business with no plan at all loses more, because every decision gets made for the first time while the clock is running.
Being ready does not require a large budget. It requires knowing three things before the bad day. You need to know who you will call, meaning an outside responder whose number is written down somewhere other than the email system that might be compromised. You need to know that your backups actually restore, because a backup that has never been tested is a hope, not a plan, and tested data backup is what turns a week of downtime into a day. And you need to know which bank contact can stop a payment, because that call is worth more than any other in the first hour.
It also helps to look honestly at where the attacker would come in. For most local businesses that is the mailbox, which is why email security that flags fake login pages and odd sign-ins from unfamiliar places tends to pay for itself faster than almost anything else. If you are not sure where your gaps are, our team in McKinney works with businesses across Plano, Frisco and the rest of Collin County, and a short security assessment will tell you what an attacker would find first. If something already looks wrong, such as a customer asking about changed bank details, a sign-in alert you do not recognize, or an invoice you did not send, do not wait to be sure. Call us at 512-518-4408 or reach out through our contact page, and we will help you contain it today.
Frequently Asked Questions
What happened in the City of Dallas ransomware attack?
In May 2023 a ransomware group called Royal encrypted City of Dallas systems after spending weeks inside the network using a stolen account and copying data out. Police dispatch went to manual operation, municipal courts closed, and several public services went offline while the city contained the attack. The city later reported that personal information for more than twenty-six thousand people was exposed and approved roughly eight and a half million dollars to respond.
Why should a small business care about a cyber attack on a city?
Because the way attackers got in, through an account that worked, is the same way they get into small businesses, and the data stolen from large organizations is reused to target the businesses and people connected to them. If you invoice, supply or work with a breached organization, your details may be in what was taken. Expect more convincing fake invoices and payment change requests for months afterward.
What should I do first if I think our business email has been hacked?
Reset the password, sign the account out of every session, and check for forwarding rules the attacker may have added. If any money has moved, call your bank immediately, because payment recalls only work in a short window. Then preserve the evidence and bring in an incident response team before you wipe or rebuild anything.
Do we have to tell customers if our email was used to send a fake invoice?
In most cases you should, and quickly, even if no law requires it for that specific situation. A short phone call telling customers not to act on any payment instruction until they confirm it by phone can stop a loss that would otherwise land on them and damage the relationship. If customer personal information was exposed, Texas breach notification rules may also apply, so get advice before you send anything in writing.
Need Help With This?
Innovation Network Design helps businesses across McKinney, Dallas, and nationwide with expert cybersecurity services.
Mark Sullivan
Innovation Network Design
With nearly a decade in cybersecurity and IT infrastructure, our team delivers expert insights to help businesses in McKinney, Dallas, and across DFW make informed security decisions. Have a question? Get in touch.
Ready to Secure Your Business?
Get a free security assessment and find out where your organization stands.