‘This is a wake up call' Cyber security expert weighs in on City of Abilene cyber attack
ABILENE, Texas ()- On Friday, April 18th, 2025, The City of Abilene became aware of a cyber attack on city computer systems. Now, more than a month later, the investigation into that attack is ongoing, and an alleged deadline has come and gone the city stating no intention to pay any would-be ransom for the stolen data. KTAB/KRBC sat down with Cybersecurity expert and CEO of CyberCatch, Sai Huda, for insight into how attacks like this one have played out in the past and what might lie in the city's future.
'This is a wakeup call for the City of Abilene,' Huda said.
Despite today's deadline, City of Abilene says they still won't pay ransom in cyberattack
The City has been relatively quiet on the matter as investigation has been conducted but that's not without reason. Because this attack involves data theft and security measures, city staff is exercising an abundance of caution to mitigate the extent of the attack within city systems and prevent the investigation from becoming compromised. With that in mind, lets discuss what we know so far.
What is a Ransomware attack?
How has the City responded?
What is at risk?
What can we do now?
This kind of malicious software is something that Huda is quite familiar with, telling KTAB/KRBC that it is not uncommon for an entity such as the City of Abilene to be targeted by such an attack.
'Very typical these days where the attackers, the bad actors, install the ransomware into the system, shut down file systems. But while they do that, they also are able to make a copy of valuable data and exfiltrate that. In other words, transmit that out, and then they'll use that to threaten the victim. In this case, the city of Abilene and say, hey, pay this ransom by this deadline. Otherwise, we will not only leave you encrypted and so you won't be able to access any file systems, but also will start to sell that data on the dark web or release it publicly in increments to embarrass you. And it's all about really money at this point,' said Huda.
Cyber Security watchdog group, Comparitech published a research article into the Abilene Cyber attack in which they were able to identify the Russian-based ransomware group Qilin as having claimed responsibility for the attack.
City of Abilene doesn't dispute report of cyber attack ransom from Russian ransomware gang
In that same article, Comparitech states that Qilin mainly targets victims through phishing emails to gain access to computer systems and introduce the malicious software. The group claiming responsibility for 25 confirmed ransomware attacks in 2025 to date. Seven of which were against government entities all across the U.S.
An initial news release put out by the City of Abilene states that, 'upon receiving reports of unresponsive servers City staff began immediately executing the incident response plan in place. Affected servers and critical assets were disconnected from the network to mitigate further spread of the attack. And an investigation with 'industry-leading cybersecurity experts' was launched.
Cyber incident disrupts City of Abilene's network systems, including phones
Since that day the City IT department has been working to restore affected city services and minimize downtime. Some systems were taken offline intentionally out of an abundance of caution, again to mitigate spread.
While the city has neither confirmed nor disproven the claims of an alleged ransom placed on the data and deadline of May 27th, 2025 to pay that ransom. A statement was put out by the City of Abilene saying, 'the City of Abilene administration reiterates that it has decided no ransom will be paid related to the cyber incident that began on April 18, 2025. The city administration has collaborated closely with cybersecurity experts and legal counsel to reach this determination.'
Huda says that he feels this was the right decision for the city to make as he has seen similar situations play out to undesirable outcomes when the ransom is paid.
'I think the city is doing the right thing which is not to pay the ransom because then that's sort of paying for bad behavior. you're rewarding for bad behavior,' Huda going on to say, 'some of the victims, which include cities, have paid the ransom simply because they've done a cost benefit analysis and said, you know what? It's gonna cost us this much money and time to recover when the impact is so severe. So let's just pay the ransom, get the decryption keys, unlock the files, and, you know, we're going to have to have a good faith that these guys will not sell that data. They'll destroy it. So some of them, unfortunately have paid. But, we're seeing a trend now which is positive that they're not paying the ransom.'
Huda stating that even if the city decided to pay the ransom there is no guarantee that the stolen data would have been released.
'And a lot of times the ransomware gangs actually will go away. All of a sudden they're gone they've taken the ransom payment. They haven't provided the decryption keys and they certainly haven't destroyed the data. So, you know, they're really not trustworthy to begin with. And so why reward them?' Huda said.
With an entity like the City of Abilene that has connections to businesses, non-profits, and direct interaction with individuals, the data that was targeted could span a wide range of fields as Huda explained.
'In this case City of Abilene's customers. They could be businesses they could be individuals and as much information about them as possible,' said Huda.
In his professional opinion, Abilene may have become a more high priority target for cyber attacks due to recent increased notoriety through the announcement of the A.I Project Stargate.
'The City of Abilene has now appeared, if you will, big time on the map. The project Stargate, which is the largest investment in A.I in US history, which entails building this massive data center at City of Abilene, is really of importance to these bad actors. But imagine all the people that are already involved in that project. So the construction people, the different suppliers, there are high value targets for these bad actors because maybe they can be ransomed or maybe their data could be used to infiltrate other valuable information about the data center. And when it comes online, that becomes even more valuable,' Huda said.
While there is currently no evidence to believe that Stargate and the Lancium clean compute facility played a factor in the ransomware gang's decision to target Abilene, Huda says the sheer amount of data and information that are involved in the venture are no doubt of high value to bad actors.
'So plans, designs, how those chips are being made, where they're being shipped to. What volume of chips are being made, what types? That's a really strategic importance. And so, you know, these these that actors in this case might be a criminal gang, but, you know, they may be supported by adversary nation states such as Russia,' suggested Huda.
As the City continues to investigate and address the attack that has already happened, Huda says businesses and individuals should be taking a cybersecurity inventory to defend against potential future attacks, data loss, and identity theft.
'So first of all, businesses should be proactive right now and think that they possibly could be attack, target and therefore put some measures in place. So like an incident response plan, which is basically a plan that says, hey, can we recognize a potential incident happening? And if we do, can we quickly come together and prevent that ransomware, for example, from infecting all of our computers?…Backup files should be regularly backed up. They should be offsite, offline, inaccessible to the ransomware, because frequently the ransomware will actually be programed to hunt for those backup files,' Huda said.
Huda advised individuals who may have been impacted by the attack to check their passwords and consider changing any passwords that are linked to City of Abilene accounts. Stating also that passwords should be varied between different accounts and not be made simple or easy to guess.
As far as any potential fallout from this attack for Abilene citizens, Huda says to be on guard for identity theft and keep a close monitor on all financial or banking accounts you utilize.
'Individuals should, number one be paying attention to their credit reports. Put a credit monitoring alert on. Maybe put some credit freezes but be especially on guard for potential identity theft. That could happen not necessarily from this gang, but, you know, other gangs, other criminals that they may sell that data to who may perpetrate that type of fraud, which is identity theft. Open up credit cards, open up bank loans, different types of other expenses, you know, using the identity of the consumer. So that's the risk to the consumer,' said Huda.
Prior to this report, KTAB/KRBC reached out to the City of Abilene with a list of questions. City staff stated that they are actively working to gather the relevant information, but were unable to respond in time for this report.
Copyright 2025 Nexstar Media, Inc. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


New York Post
35 minutes ago
- New York Post
Trump says he has group of ‘very wealthy people' to buy TikTok, predicts China will approve deal
WASHINGTON — President Trump said in a Fox News interview broadcast on Sunday that he had found a buyer for the TikTok short-video app, which he described as a group of 'very wealthy people' whose identities he will reveal in about two weeks. Trump made the remarks in an interview on Fox News' 'Sunday Morning Futures with Maria Bartiromo' program. He said the deal he is developing would probably need China's approval to move forward and he predicted Chinese President Xi Jinping would likely approve it. Advertisement President Trump said in an interview that he has found a buyer for TikTok. / MEGA The president earlier this month had extended to September 17 a deadline for China-based ByteDance to divest the US assets of TikTok despite a law that mandated a sale or shutdown without significant progress. A deal had been in the works this spring that would have spun off TikTok's US operations into a new US-based firm, majority-owned and operated by US investors, but it was put on hold after China indicated it would not approve it following Trump's announcements of steep tariffs on Chinese goods. Advertisement 'We have a buyer for TikTok, by the way,' Trump said. 'I think I'll need probably China's approval. I think President Xi will probably do it.' A 2024 US law required TikTok to stop operating by January 19 unless ByteDance had completed divesting the app's U.S. assets or demonstrated significant progress toward a sale. Trump described the potential TikTok buyer as a group of group of 'very wealthy people.' REUTERS/Dado Ruvic/Illustration/File Photo Trump, who credits the app with boosting his support among young voters in last November's presidential election, has extended the deadline three times.


UPI
3 hours ago
- UPI
Ukrainian F-16 pilot killed in major Russian airstrikes
June 29 (UPI) -- A Ukrainian F-16 pilot died overnight Sunday during one of Russia's largest attacks since the invasion in 2022 that included several hundred drones and missiles, Ukraine's Air Force said. Lt. Colonel Maksym Ustymenko, 31, died after his fighter jet was damaged trying to intercept Russian missiles and drones, Ukraine's Air Force said. Ustymenko, who destroyed seven enemy air targets and managed to steer his jet away from populated areas but didn't eject in time. "Ustymenko did everything possible, but his jet was damaged and started losing altitude. He died like a hero!" Ukrainian military officials said. Ustymenko became Ukraine's third F-16 pilot to die in combat since the nation added U.S.-made planes last year. Russia attacked Ukraine with 537 missiles and drones, including 477 Shad-type attack drones and decoys launched into Russian-occupied Crimea, the Kiev Post reported from the military. Of those, 475 were shot down, including Shahed drones and 225 drones suppressed by electronic warfare. Russia's missile attack lasted nearly three hours and the drone siege went on for almost 10 hours. A Ukrainian drone strike on Russia's Kirovske airfield in Crimea destroyed several helicopters and an air defense system, the Security Service of Ukraine said. "The SBU is systematically working to reduce the Russian Federation's capabilities to carry out air and bombing strikes on the territory of Ukraine," the military said. "The occupiers must realize that their expensive military equipment and ammunition are not protected anywhere: neither on the front line, nor in temporarily occupied territories, nor in the enemy's deep rear." The agency said Mi-8, Mi-26 and Mi-28 helicopters were destroyed. A dozen Ukrainians were injured in attacks against infrastructure, residential buildings and storage buildings in Lviv, Poltava, Kharkiv, Kherson, Mykolaiv and Kyiv. Several explosions were reported in Kremenchuk and Lviv. And an industrial facility in the Poltava region caught fire as a result, officials said. A production site in Zaporizhzhia also was damaged. Russia, under Russian President Vladimir Putin, has increased its attacks on Ukraine's cities during a summer offensive, Politico Europe reported. "Just this week alone, there have been more than 114 missiles, over 1,270 drones, and nearly 1,100 glide bombs," Zelensky said on Telegram. "Putin long ago decided he would keep waging war, despite the world's calls for peace." Neighboring Poland, a member of NATO, scrambled jets and activated its ground-based air defense system, its military said. Zelensky urged more protection from its allies, including ballistic missiles, and efforts to end the war. "Ukraine must strengthen its air defense -- the thing that best protects lives," Zelensky said. "These are American systems, which we are ready to buy. We count on leadership, political will, and the support of the United States, Europe, and all our partners. I thank everyone who is helping." Last week during the NATO summit in The Hague, Netherlands, U.S. President Donald Trump said the U.S. might be able to provide anti-ballistic missiles. "We're going to see if we can make some available," Trump said. "They're very hard to get. We need them too. We were supplying them to Israel, and they're very effective. A hundred percent effective -- hard to believe how effective." The F-16 is a single-engine, single-seat supersonic jets have been produced by Lockheed Martin since 1976.


Los Angeles Times
3 hours ago
- Los Angeles Times
Russia launches the biggest aerial attack since the start of the war, Ukraine says
KYIV, Ukraine — Russia launched its biggest aerial attack against Ukraine overnight, a Ukrainian official said Sunday, part of an escalating bombing campaign that has further dashed hopes for a breakthrough in efforts to end the 3-year-old war. Russia fired a total of 537 aerial weapons at Ukraine, including 477 drones and decoys and 60 missiles, Ukraine's air force said. Of these, 249 were shot down and 226 were lost, probably having been electronically jammed. The onslaught was 'the most massive airstrike' on the country since the beginning of Russia's full-scale invasion in February 2022, taking into account both drones and various types of missiles, Yuriy Ihnat, head of communications for Ukraine's air force, told the Associated Press. The attack targeted several regions, including western Ukraine, far from the front line. Poland and allied countries scrambled aircraft to ensure the safety of Polish airspace, the country's air force said. Three people were killed in each of the drone strikes in the Kherson, Kharkiv and the Dnipropetrovsk regions, according to their governors. Another person was killed by an airstrike in Kostyantynivka, local officials said. In addition to aerial attacks, a man died when Russian troops shelled the city of Kherson, and the body of a 70-year-old woman was found under the rubble of a nine-story building hit by Russian shelling in the Zaporizhzhia region. In the far-western Lviv region, a large fire broke out at an industrial facility in the city of Drohobych following a drone attack that also cut electricity to parts of the city. Ukraine's air force said one of its F-16 warplanes supplied by its Western partners crashed after sustaining damage while shooting down air targets. The pilot died. Russia's Defense Ministry said it had shot down three Ukrainian drones overnight. Two people were wounded in another Ukrainian drone attack on the city of Bryansk in western Russia, regional Gov. Alexander Bogomaz said Sunday morning, adding that seven more Ukrainian drones had been shot down over the region. Meanwhile, Russia claimed Sunday that it had taken control of the village of Novoukrainka in the partially Russian-occupied Donetsk region. Russian forces have been slowly grinding forward at some points on the roughly 620-mile front line, though their incremental gains have been costly in terms of troop casualties and damaged armor. In other developments, Russia's foreign intelligence chief, Sergei Naryshkin, said he had spoken on the phone with his U.S. counterpart, CIA Director John Ratcliffe. 'I had a phone call with my American counterpart and we reserved for each other the possibility to call at any time and discuss issues of interest to us,' Naryshkin said in remarks to state TV reporter Pavel Zarubin, who posted them on his Telegram channel Sunday. Sunday's attacks follow Russian President Vladimir Putin's comments two days ago that Moscow is ready for a fresh round of direct peace talks in Istanbul. Two recent rounds of talks between Russian and Ukrainian delegations in Istanbul were brief and yielded no progress on reaching a settlement. Ukrainian President Volodymyr Zelensky signed a decree to withdraw Ukraine from the Ottawa Convention banning antipersonnel land mines, a Ukrainian lawmaker said Sunday. The move follows similar recent steps by the Baltic states and Poland. The 1997 treaty prohibits the use, production, stockpiling and transfer of antipersonnel land mines in an effort to protect civilians from explosives that can maim or kill long after fighting ends. 'This is a step that the reality of war has long demanded,' said Roman Kostenko, secretary of the Ukrainian parliamentary committee on national security, defense and intelligence. He noted that Russia is not a party to the convention 'and is massively using mines against our military and civilians.' Yurchuk writes for the Associated Press.