Duvall Fire District hacked; Snoqualmie pays ransom

Hackers submitting faked invoices to local fire districts got at least one payoff, and taught local agencies a lesson in network security.

Hackers submitting faked invoices to local fire districts got at least one payoff, and taught local agencies a lesson in network security.

On Jan. 22, the city of Snoqualmie, which provides information technology services to King County Fire Protection District 45, paid a ransom of $750 to hackers who had taken control and encrypted files on a computer at the fire district. The ransom was required to unlock a computer on the district’s network, which was encrypted Jan. 7, when an employee clicked a link in a fake e-mail message.

The e-mail looked like an invoice from the fire district’s dispatch center, said Fire Chief David Burke. When an employee opened the email and clicked the link, a program started encrypting all the files on that computer.

Burke said the scam email was nearly identical to the real invoices the district receives for dispatch services.

The attack did not affect essential files.

“None of the financials, payroll, none of those things were accessible,” Burke said. “It was more of our daily documents, policies procedures, etc.”

Snoqualmie’s IT department helped the fire district handle the situation. Snoqualmie contacted the FBI which recommended that they pay the ransom. However, the hackers would accept payment only through bitcoin, a decentralized digital currency.

Burke said Snoqualmie IT went to Tacoma to get the money exchanged to bitcoin. Once the ransom was paid, the department received a decryption key and began to retrieve their files.

Both Burke and Snoqualmie Mayor Matt Larson said trying to recreate the files would have taken too much time and effort compared to the relatively small ransom.

“They had importance to the agency, trying to rebuild them would have been a considerably greater expense than paying the ransom,” Larson said.

Typically, Burke said, a backup system would have prevented the need to pay a ransom, but the fire district was in the process of modernizing their systems and backups had not been implemented yet.

“If our backup had been in place we would have been inconvenienced half a day or less,” he said. “The city of Snoqualmie stepped up and took care of everything and paid the decryption code. Snoqualmie went heads and shoulders above what our expectations were, they honored their part of the contract and more.”

With their files back, the fire district has a backup system up and running and is doing more training on Internet safety with employees. According to Burke, neighboring fire departments were also targeted, possibly through a mailing list containing information on the various fire chiefs in the region.

“The agency serves a lot of fire departments in the area and all of them got it. The email distribution for fire chiefs was compromised. Some of them caught it and were able to back up. Some of them handled it in house,” Burke said. “As soon as it started they were able to shut it down and restore it within a couple of hours.”

Burke doesn’t believe that the dispatch service was compromised and said the hackers could have gotten their information from any of the agencies working with the service.

After this incident the service has changed the formatting of invoices and moved to a PDF format.

“We have taken care of training and taking invoices in a new way,” Burke said. “We’ve done everything we believe we can, but the education will continue that we will give to all of our personnel.”


In consideration of how we voice our opinions in the modern world, we’ve closed comments on our websites. We value the opinions of our readers and we encourage you to keep the conversation going.

Please feel free to share your story tips by emailing editor@valleyrecord.com.

To share your opinion for publication, submit a letter through our website https://www.valleyrecord.com/submit-letter/. Include your name, address and daytime phone number. (We’ll only publish your name and hometown.) We reserve the right to edit letters, but if you keep yours to 300 words or less, we won’t ask you to shorten it.

More in News

NW Carpenters Union members strike in front of downtown Bellevue construction site (photo by Cameron Sheppard)
Carpenters union strike interupts some prominent Eastside construction projects

Union representative says members are prepared to strike “as long as it takes.”

Map of proposed landfill expansion sites (screenshot from King County website)
Waste management expert knocks county’s plan to expand landfill

The waste management advocate said the decision to expand seems pre-determined despite assessment.

Participants in fundraiser previous event (courtesy of Alzheimer’s Association Washington State Chapter)
Walk To End Alzheimer’s returns to Eastside on Sept. 25

Alzheimer’s Association moves forward with plans for an in-person event.

file photo
State employees including first responders sue state over vaccine mandate

The lawsuit filed on behalf of more than 90 plaintiffs claims Inslee’s order is unconstitutional.

Masked spectators watch Mount Si’s Sept. 10 football game against Yelm High School. Photo Courtesy of Calder Productions.
Snoqualmie Valley schools deal with COVID cases, staffing shortages

Enrollment numbers rose as students in the Snoqualmie Valley School District successfully… Continue reading

North Bend City Council. 	Courtesy photo
North Bend limits restrictions on low-income housing

The North Bend City Council unanimously passed an ordinance Sept. 7 in… Continue reading

Cars lined up at Snoqualmie Valley Hospital on March 26, 2021, as people awaited their first dose of the Moderna COVID-19 vaccine as part of the hospital’s first mass vaccination event. File Photo contributed by Snoqualmie Valley Hospital.
Valley COVID case rates decrease, but remain high

COVID-19 case rates across the Snoqualmie Valley decreased in some areas over… Continue reading

Pixabay photo
Union carpenters to go on strike, expected to impact Eastside Microsoft projects

Members authorized strike after rejecting AGC offer for the fourth time.

Most Read