Desk scene with laptop showing 'All your files are encrypted' ransomware message, papers, and a lamp on a stormy night.

Cyber Horror Stories, Part 2. The ransom was $76,000. Saying no cost $18 million, and the attackers had nothing to do with the difference.


Tuesday morning, May 7, 2019, Baltimore city employees log in and find every file locked behind a ransom note. The price to unlock one system is three bitcoin, and the price for all of them is thirteen (about $76,000 at the time).

Mayor Jack Young says the city will not pay, which on principle was the right call. What nobody in the room knew yet was that it was about to cost $18 million, and not because of anything the attackers did.

How It Happened

The ransomware was RobbinHood, and within hours it had taken a city of 600,000 people back to paper. For the better part of a month:

  • Water bills, property taxes, and parking tickets could not be paid online
  • Roughly 1,500 home sales stalled because the city could not verify liens
  • Speed camera tickets were payable only in person, with the paper ticket in hand
  • Prosecutors requested drug, DNA, and gun test results from police by hand
  • About 10,000 employee logins were still being rebuilt a month later

By June the mayor put the damage at over $18 million, including at least $8 million in revenue the city could not collect…but none of that is the horror story.

The horror story came out in September. A city audit, reported by the Baltimore Sun, found the IT department had no cloud backup and no recovery mechanism for much of the city’s critical data. Employees had been saving files to their own computers, and in many cases those hard drives held the only copy, so when RobbinHood encrypted them there was simply nothing to restore. The attack did not destroy the city’s backups; the city had simply never made any. When the audit findings were read into the record, one councilman’s reaction was, “Wow. That’s mind-boggling to me.” (Our reaction exactly, except we probably would not have said it so politely.)

In other words, Baltimore did not refuse the ransom because it had a recovery plan; it refused, and then found out it did not have one. The attacker pleaded guilty in federal court in 2025, and the city now carries $20 million in cyber insurance at $835,000 a year.

It’s Still Happening

Five weeks after Baltimore, Florida had three of its own…and this week, a sequel.

1) Lake City, June 2019

Forty-five minutes up I-75 from our Gainesville office, Ryuk took out the city’s servers, phones, and email on June 10. Lake City did have backups, but they were deleted during the attack because they sat on the same network with the same credentials as everything else. After two weeks of trying to recover anyway, the city declared many systems unrecoverable. The council then voted unanimously to let its insurer pay 42 bitcoin (about $460,000). The IT director had been fired three days earlier.

2) Riviera Beach and Key Biscayne, Same Month

Riviera Beach, in Palm Beach County, had already voted to pay about $600,000 after someone clicked on an email, and Key Biscayne was hit just days after Lake City. Three Florida city halls, one June.

3) Hollywood, Florida, This Week

On October 7, federal prosecutors indicted the owner of MonsterCloud, a ransomware recovery firm that told victims it could decrypt their files without paying the criminals. According to the indictment, it was paying the criminals and billing the markup: more than $19 million charged to clients against roughly $8 million in ransoms. In one case, an $8,200 ransom became a $150,000 invoice. The charges are allegations and he is presumed innocent, but the business model itself is not in dispute, and it only works on clients whose backups were not there.

The Average Now

Sophos surveyed nearly 3,000 ransomware victims and found that attackers went after the backups in 94% of cases and succeeded 57% of the time. When they succeeded, the median recovery cost jumped from $375,000 to $3 million. Whether a business then pays the attacker, the fixer, or the consultants, it pays, which is why a recovery plan built on the assumption that the network is already gone is the only version where the number stays small.

What Would Have Stopped It

  • Nothing lives only on a laptop. Baltimore’s problem was not a bad backup; it was files that had never been backed up at all. If a document matters, it lives somewhere that gets copied, and employees should not have to think about it.
  • One copy the network cannot reach. Lake City’s backups were deleted because the attacker could get to them. The standard is three copies of the data on two different kinds of storage, with one of those copies either offline or locked so it cannot be changed or deleted. That copy also gets its own login and its own MFA, so an attacker who owns the network still does not own the backup.
  • A restore test with a date on it. Lake City spent two weeks finding out what was recoverable, while Baltimore spent a month. A quarterly test answers that question on a Tuesday afternoon instead of in an emergency council meeting.
  • A recovery-time number everyone has seen. If the honest answer is “weeks,” that is the budget conversation. Plus, it a lot cheaper than $460,000, $18 million, or a $150,000 invoice from a firm that paid $8,200.

The Ransom Is Never the Bill

Baltimore refused to pay and spent $18 million, Lake City paid and still lost systems for good, and MonsterCloud’s clients thought they were avoiding the ransom and paid eighteen times over. In every version, the ransom note was the cheapest number in the story. The expensive part was decided years earlier, by whoever did or did not make sure there was a second copy somewhere the attacker could not reach.


Where GiaSpace Fits

We build backup and recovery for Florida businesses on the assumption that the network is already lost: one copy offline, backup credentials separate from everything else, nothing living only on a laptop, and a restore test on the calendar rather than a hope.

→ Schedule a Backup and Recovery Review with Rob Giannini, our CEO & Founder

→ Learn More About Our Business Continuity Services

Struggling To Find A Great IT Company?

Fill in Below. We Get Back to You in Minutes

Want content like this delivered straight to your inbox?

IT insights, cybersecurity alerts, and tech tips for business leaders. No fluff, no spam.
Get IT Help Now