Is Hamilton Prepared for the Cost of Recovering from a Cyberattack?
- Mahnoor Khakwani
- Apr 2, 2024
- 4 min read
Mayor Andrea Horwath and City Manager Marnie Cluckie provided an update confirming that the attack is still ongoing, preventing staff from accessing certain IT systems

Hamilton's mayor, Andrea Horwath, has assured residents that the city will not be paying a ransom to the perpetrators of the recent cyberattack that disrupted municipal operations for nearly three weeks. While Horwath did not disclose the specific amount demanded, she characterized it as a significant sum, stating it was a "whole hell of a lot of money."
She also acknowledged that regardless of the ransom, the cost of recovering the systems impacted by the attack would be substantial. However, she emphasized the city's commitment to ensuring that necessary measures are taken to protect the city and its residents, even if it means significant expenses.
Horwath refrained from revealing too many details during the update, citing the severity of the situation and the sophistication of the cybercriminals involved. She described the challenges faced by the city as "hardcore stuff" and acknowledged the perpetrators as "pretty sophisticated" criminals.
The update underscores the seriousness of the cyberattack and the complexities involved in responding to such incidents, highlighting the importance of robust cybersecurity measures and preparedness in safeguarding municipal systems and data.

"I know that's a sore spot for folks, I get that. I wish I could just kind of have every answer and just put it all out into the metaverse, but we don't want to put our city at any more risk," said Mayor Andrea Horwath, addressing concerns about the lack of detailed information regarding the cyberattack. She emphasized the city's priority of safeguarding its systems and data from further harm.
City Manager Marnie Cluckie reassured the public that staff and third parties are working diligently "around the clock" to restore systems affected by the attack. She mentioned that a forensic analysis has indicated no compromise of personal data tied to residents. However, Cluckie also emphasized the city's commitment to transparency, stating that if any evidence suggests otherwise, they will promptly inform the public.
Cluckie explained that while the city's data was encrypted during the attack, there is no evidence to suggest that personal data was removed from the systems or compromised. She further elaborated that the incident response plans implemented by the city involved taking several services and systems offline to mitigate damage and protect critical infrastructure.
Moreover, Cluckie mentioned that partners are still engaged in the ongoing process of restoring and rebuilding systems affected by the attack, highlighting the complexity and time-intensive nature of the recovery efforts. This update provides insight into the city's proactive response to the cyberattack and its commitment to addressing the situation transparently while prioritizing the security of residents' data and municipal operations. As investigators continue to assess the full extent of the cyberattack, specific details about the number of city systems experiencing outages have not been provided.

In response to the disruption, the city has implemented "old school" manual operations to ensure the delivery of some services, accommodating the needs of the public. While city phone lines remain impacted, the customer contact center remains operational and is able to handle calls.
All municipal service centers remain open to the public, and requests for various services such as marriage licenses, taxi scripts, and burn permits are still being processed manually to minimize inconvenience to residents.
Additionally, recreational facilities including recreation centers, senior centers, arenas, and golf courses continue to operate citywide, ensuring that community services remain accessible.
Fire Chief Dave Cunliffe highlighted the significant impact of the attack on emergency services, stating that it has required an "all hands on deck" approach from his staff. Firefighters have had to resort to "old-fashioned" methods to respond to calls, emphasizing the challenges posed by the disruption to essential services.
Fire Chief Dave Cunliffe explained that firefighters are utilizing map books and cross streets, resorting to traditional methods for navigation. Additionally, cellphones in fire trucks provide limited access to resources like Google Maps, aiding in navigation during emergency responses.
Hamilton Police Deputy Chief Ryan Diodati assured that the dispatch process for officers remains unaffected as it operates through a separate data management system, ensuring uninterrupted service.
Paramedics Deputy Chief Russell Crocker stated that calls for paramedics have not been impacted either, as they are managed by a provincial system operated by the Ministry of Health.
Chief Digital Officer Cyrus Tehrani discussed the city's restoration process, mentioning the use of backups from safe points as part of the recovery efforts. He acknowledged the complexity of ensuring data safety and security, describing it as a "balancing act." Tehrani emphasized that the restoration process varies for each system, with some being straightforward while others may pose challenges, depending on their individual characteristics and requirements.Hamilton's city manager, Marnie Cluckie, has announced that the overtime and stand-by pay for front-line workers and other applicable staff, which was disrupted due to the cyberattack, will be addressed in the next pay cycle. This development comes after several weeks during which the option for overtime pay was unavailable, raising concerns among union leaders who advised members that they could decline extra hours if not compensated.

Cluckie explained that the resolution process will be conducted manually, as the online systems associated with payroll remain offline due to the cyberattack. The manual input process is expected to be operational by March 29, albeit Cluckie acknowledged that it may not be perfect given the shift to manual procedures. However, she assured that every effort will be made to ensure accurate and timely payments, with any inaccuracies addressed promptly.
In terms of the criminal investigation into the ransomware attack, Hamilton police have confirmed their role as the lead agency. Deputy Chief Ryan Diodati confirmed that the investigation was launched on March 1, with partners including the Ontario Provincial Police (OPP) and the Royal Canadian Mounted Police (RCMP). This update highlights the ongoing efforts to address the aftermath of the cyberattack, both in terms of restoring operations and pursuing legal action against those responsible.
Deputy Chief Ryan Diodati emphasized the sophistication of the criminals behind the cyberattack, highlighting the complexity of the investigation. He stated that gathering evidence is an ongoing process, and the investigative team will continue to follow leads and gather evidence to pursue those responsible.
Marnie Cluckie previously informed Global News that Cypfer, a technical adviser, is part of the forensic investigation and incident response team, collaborating with the police, legal counsel, and insurers. This collaborative effort underscores the comprehensive approach being taken to understand the nature of the attack, identify the perpetrators, and mitigate the impact on the city's systems and operations.
Comments