articles
Aug 13, 2026

Share
In 2024, four ransomware incidents hit property tax and public safety systems across the country. Tarrant County, TX. Bucks County, PA. Columbus, OH. Coeur d’Alene, ID. They all followed the same pattern.
Each attack was against legacy on-prem systems with a direct line to resident-facing services.
Those four incidents aren’t outliers. According to Sophos, when ransomware hits state and local government, it almost always succeeds. 98% of attacks locked agencies out of their own data in 2024, with an average recovery cost of $2.83M.
For agencies still running on-premises infrastructure, the pattern is avoidable. Cloud property tax platforms close the gaps that attackers consistently exploit. This article examines each incident, the shared vulnerabilities behind them, and what moving to the cloud actually changes.
Property tax systems hold some of the most sensitive data in local government. Every record carries full PII for an entire homeowner base, including social security numbers, driver’s license numbers, and banking and mortgage details. That data is private and valuable to residents—and therefore cybercriminals as well.
When attacks impact public services, they give ransomware groups leverage, forcing governments to choose between limiting services or paying the ransom. That’s why property tax systems are targeted. The tax revenue funds schools, roads, and emergency services. When a system goes down, every department depending on that revenue feels it.
Not only that, many property tax platforms still run on-premises without automatic patching. That’s the exact infrastructure profile that ransomware groups look for. Unpatched systems with direct access to sensitive data are both vulnerable and lucrative.
State and local government had the highest ransomware data encryption rate of any sector in 2024 at 98%. The average recovery cost was $2.83M—more than double the $1.21M reported in 2023.
Ransomware local government incidents are only accelerating. According to Comparitech’s H1 2025 Government Ransomware Roundup, 208 ransomware attacks hit government entities worldwide in the first half of 2025 alone. That’s a 65% increase over the same period in 2024 and a 25% increase over the second half of 2024.
Of those 208 attacks, 72 targeted U.S. entities—more than a third of the global total.
Government cybersecurity has become one of the most targeted areas in cybercrime, and the volume keeps rising. Ransomware groups are drawn to government agencies for the same reasons they’re drawn to property tax systems specifically: valuable data, operational leverage, and infrastructure that often lags behind in data security.
Each of the following incidents is part of a larger pattern. If your agency runs legacy on-premises infrastructure, you should take note.
The Akira group disabled Bucks county’s CAD dispatch system. 911 calls stayed operational, but dispatchers reverted to pen and paper for nine days while the Pennsylvania National Guard assisted with recovery.
A ransomware attack took the city’s website and phone systems offline for more than a week. Fifty-seven residents were notified that their SSNs and driver’s license numbers had been exposed.
The Medusa ransomware group hit Tarrant County’s appraisal district and demanded $700,000. The county refused to pay, and Medusa leaked taxpayer data to the dark web. During the outage, the appraisal record search system went offline, taking resident-facing property tax services with it.
The Rhysida group breached city systems and claimed 6.5 TB of data stolen. After a failed ransom auction, over 3 TB was leaked, exposing personal data from roughly 500,000 residents.
All four incidents had something in common. Each agency was running legacy, on-premises infrastructure with a direct connection to resident-facing services.
The architecture difference between on-prem and cloud-based systems matters more than most agencies realize.
An on-premises property tax system is typically built around one physical server (or a small cluster) in one location. That server is patched on IT’s schedule, which often means weeks or months between updates. When attackers find an unpatched vulnerability, everything routed through that server stops. There’s no failover, no redundancy, and no way to isolate the breach without taking the system down.
Cloud-native infrastructure works differently. Resources are distributed across multiple regions with no single server to target. Security updates are continuous and automatic—no patch cycle and no window of exposure. If one node is compromised, the system routes around it.
Bucks County illustrated the risk of on-prem. Restoring a single CAD environment was the recovery bottleneck. For nine days, they reverted to pen-and-paper dispatch while the system came back online. In a cloud environment, that attack surface doesn’t exist in the same way. Distributed infrastructure and automatic failover change what a successful breach can actually take offline.
CentralSquare Property Tax is AWS government software, and it eliminates the on-premises vulnerabilities behind each of the four incidents above. The architectural difference is important across several dimensions.
Multi-region data replication means there’s no single point of failure and no gap in the record if a system goes down. Bucks County’s nine-day outage was a single-server problem, which cloud environments don’t suffer from.
Software patches apply continuously, closing vulnerabilities as they’re identified—not on a monthly or quarterly IT cycle. In other words, there’s no patch window, and therefore, no window for attackers to exploit.
Data is encrypted at rest and in transit, built into the AWS architecture from the start. This makes property tax data security a feature of the platform, not an afterthought. In Tarrant County, attackers encrypted locally stored data and threatened to leak it. With no local server holding the data, that leverage disappears.
In a cloud environment, infrastructure management, patch deployment, and security monitoring are handled at the platform level—not by your internal IT team. That means your staff can spend more time investing in resident services.
While on-premises systems create a single point of failure, these four cloud capabilities eliminate it and save your staff time. Is your agency ready to migrate to the cloud?
The ransomware incidents in this article share more than a headline. They share inherent vulnerabilities in their infrastructure—ones that cloud-based property tax software directly addresses. No single point of failure, no unpatched exposure window, and no locally stored data to encrypt and hold hostage.
Property tax ransomware attacks have proven consistently effective, and the rate is still climbing. The four agencies cited here weren’t uniquely vulnerable. They ran the same kind of on-premises system that thousands of agencies still depend on today.
Cloud-based architecture removes those vulnerabilities at the source. CentralSquare Property Tax is a cloud property tax platform, built on AWS with the security architecture you can trust. Schedule a call today to learn how your agency can transform its property tax software security.
This website uses cookies to ensure you get the best experience on our website. By continuing on our website, you expressly consent to our use of cookies, Privacy Policy and Terms of Use. To find out more about how we use cookies, please see our Privacy Policy.