
The City of Norcross has confirmed that a ransomware attack hit its computer networks on August 1, weeks before officials publicly disclosed the incident this week. City leaders say most computer systems and services have returned to normal operations, but they have not released a timeline for fully restoring everything that was affected.
According to FOX 5 Atlanta, the City of Norcross announced that a ransomware incident affected certain computer networks, and the city notified law enforcement agencies after discovering the breach. Per city officials, Norcross also engaged external cybersecurity professionals to help investigate and respond to the attack. Officials have not stated whether a ransom demand was made, and authorities have not identified who is responsible for the attack.
What Officials Have — and Haven't — Said
City officials have not disclosed whether sensitive resident or employee data was compromised in the breach, leaving one of the most consequential questions about the incident unanswered for now. The remaining Norcross networks still being restored are experiencing limited disruptions during the recovery process, and city staff say they plan to safely restore the remaining networks while also strengthening security protocols going forward.
The timing is notable: the Norcross Mayor and City Council formally approved the city's $62.7 million FY2027 budget on August 20, according to the City of Norcross, and that spending plan specifically included new investments in public safety and cybersecurity. The $23.6 million earmarked for general operations takes effect September 1, meaning the council was funding cybersecurity upgrades just days before the city disclosed the ransomware incident to the public. Norcross is a suburban city of roughly 17,209 residents in Gwinnett County, situated near Interstate 85 in northern metro Atlanta, according to Ballotpedia, and operates under Mayor Craig Newton and a six-member city council.
State Law Sets the Next Milestones
Georgia law creates two separate reporting obligations that could shape what happens next. Under House Bill 156, codified as O.C.G.A. § 38-3-22.2, state and local government agencies are required to report cyberattacks, data breaches, or malware incidents affecting critical systems to the Georgia Emergency Management and Homeland Security Agency, according to the Georgia Technology Authority. Separately, the Georgia Personal Identity Protection Act, O.C.G.A. § 10-1-912, requires government data collectors to notify affected residents without unreasonable delay if a breach compromises unencrypted personal identifying information such as names paired with Social Security, driver's license, or financial account numbers, per Justia Law. Since Norcross has not said whether resident or employee data was exposed, it remains unclear whether that second notification threshold will be triggered.
A Regional Pattern of Municipal Breaches
Norcross's response echoes a containment tactic used elsewhere in Georgia. In July, nearby Greene County took its entire computer network offline for weeks following a cyber intrusion while outside specialists rebuilt its systems, as Hoodline reported in coverage of that shutdown, though Greene County kept 911 dispatch functional while isolating administrative servers. That same month, Georgia educational and technical entities launched a specialized Cyber Resiliency Center, according to WABE, offering threat assessment and recovery support to local governments, public schools, and rural hospitals statewide.
Metro Atlanta has faced high-stakes municipal cyberattacks before. In March 2018, SamSam ransomware paralyzed the City of Atlanta's network, and the city ultimately spent more than $2.7 million on recovery after attackers demanded a $51,000 Bitcoin ransom, per Wikipedia's account of the Atlanta ransomware attack. Gwinnett County itself has a history with these threats — commissioners approved a $456,483 data encryption contract with Dell in 2019 following intrusions targeting the Lawrenceville Police Department and Atlanta, and neighboring Loganville disclosed a 2018 server breach that potentially exposed residents' Social Security and banking information. The Norcross incident also arrives amid what researchers describe as an active nationwide wave of cyber intrusions targeting local government infrastructure, with municipalities including Fort Smith, Arkansas, reporting network disruptions this month, according to DysruptionHub.
For now, Norcross residents are left with a partial picture: an attack that happened weeks ago, a recovery that's mostly but not entirely complete, and open questions about who was behind it and what data, if any, was taken. City officials have said only that they intend to keep restoring remaining systems safely while shoring up defenses against future intrusions.








-4.webp?w=1000&h=1000&fit=crop&crop:edges)
