The City of Norcross says it identified a ransomware incident on August 1, 2026 that hit certain computer systems. The official news flash does not name a crew, a ransom, or whether resident or employee records were copied. FOX 5 Atlanta published the city’s media advisory on August 28. Hoodline (Aug 29) is the piece that made the weeks-long gap the headline. WSB-TV repeated the same official facts on Aug 29.
This is not a duplicate of Atlanta 2018 SamSam history, the Surfside Beach municipal BEC, or leak-site claim posts. Norcross confirmed ransomware. It has not confirmed a data breach of personal information. We found no matching leak-site listing and no CourtListener RECAP docket.

Snapshot
| Field | Detail |
|---|---|
| City | Norcross, Gwinnett County, Georgia (norcrossga.net) |
| Identified | August 1, 2026 (city news flash) |
| Public notice | Late August (FOX 5 Aug 28; city CivicAlert AID=2028) |
| Status | Most systems operational; limited disruptions during restore |
| Data / actor / ransom | Not disclosed |
| CourtListener | 0 matching RECAP dockets (Georgia + nationwide, searched Aug 30, 2026) |
What the city has said
The official notice is short. Staff engaged cybersecurity professionals and notified law enforcement. Restoration continues. More details later. That is the entire public forensic picture.
Hoodline is right that the calendar gap matters for residents: phishing and “city bill / tax / restore your account” mail can run for weeks while people still think City Hall is fine. Georgia also has two different clocks. O.C.G.A. § 38-3-22.2 (HB 156) requires agencies to report qualifying cyber incidents to GEMA/HS — that portal is not for private citizens. Separately, the Georgia Personal Identity Protection Act (O.C.G.A. § 10-1-912) requires resident notice if unencrypted personal identifying information was acquired. Norcross has not said that threshold was met.

The August council recap is easy to over-read. Council approved a ~$62.7 million FY2027 budget (year starts Sept 1). The $23.6 million line is the General Fund, not a cybersecurity earmark. What the city did name is a $48,100 cybersecurity assessment by CyberElite Corporation, paid from a federal cybersecurity grant, after RFP IT 26-10 (proposals due July 7, 2026). That work was already in motion before August 1. It does not prove the city was “just about to get secure.”
What residents and staff should do
- Type norcrossga.net and CivicAlert AID=2028 yourself. Do not open “Norcross restore / refund / court reset” mail.
- Pay utilities, citations, and taxes only through hosts you typed or apps you already had.
- If you get a “your SSN was in the Norcross breach” text, treat it as unverified. The city has not published a resident-data finding.
- Municipal peers: report through GEMA/HS. Residents who were actually defrauded use local police and IC3.
- Freeze credit if you later receive a named O.C.G.A. § 10-1-912 notice. Do not freeze because a stranger emailed you.
MFA: YubiKey and Google Authenticator
A hardware key does not decrypt a ransomware-locked file server. It does stop a lot of the follow-on phishing that shows up after a city headline: CivicPlus website accounts, vendor logins, and staff mail.
| Platform | Grade | YubiKey | Authenticator |
|---|---|---|---|
| CivicPlus account | Pass | No | Yes |
| Norcross website mail | Unevaluated | Not documented | Not documented |
CivicPlus (updated July 1, 2026) names Google Authenticator and other TOTP apps for account.civicplus.com. Email one-time codes are the documented fallback. YubiKey / FIDO and account passkeys are not documented. 2FA can be required by the organization; it is not automatically on for every CivicEngage “Website Sign In” resident account.
City mail for norcrossga.net goes to AppRiver (*.arsmtp.com), not a published Microsoft 365 MFA page we can grade. We do not invent a YubiKey path for staff Outlook.
Directory: MFA support directory · Category → Business Apps.
Recommended MFA tools
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Independent cybersecurity audits
We audited city, county, vendor, and state-program hosts on August 30, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not say whether a file server was encrypted.
| Organization | Domain | Overall | vs 100% |
|---|---|---|---|
| City of Norcross | norcrossga.net | 60% | −40 |
| Gwinnett County | gwinnettcounty.com | 57% | −43 |
| CivicPlus | civicplus.com | 43% | −57 |
| GEMA/HS (program host) | gema.georgia.gov | 29% | −71 |
| Domain | Identity | Transport | Website |
|---|---|---|---|
| norcrossga.net | 50% | 15% | 65% |
| gwinnettcounty.com | 25% | 15% | 87% |
| civicplus.com | 25% | 45% | 37% |
| gema.georgia.gov | 0% | 15% | 40% |
Audit links: norcrossga.net · gwinnettcounty.com · civicplus.com · gema.georgia.gov
gema.georgia.gov and gta.georgia.gov are georgia.gov program hosts with no MX and Identity 0% — do not treat a 29% score as “GEMA was breached.” The city’s own host is the one residents should type. Both city and county show 15% Transport (MTA-STS / related), which makes spoofed “restoration update” mail easier to deliver.
DNS MX for norcrossga.net (Aug 30, 2026): norcrossga.net.1.0001.arsmtp.com and a secondary hostname orcrossga.net.2.0001.arsmtp.com (missing the n). That is an AppRiver-style label, not proof of a squat. Still: confirm mail paths after a ransomware event.

Website stack note
Passive website-tech probes on August 30, 2026:
| Domain | Stack signal |
|---|---|
| norcrossga.net | ASP.NET (CivicEngage); Let’s Encrypt TLS expires 2026-11-26 |
| civicplus.com | Stack undetected; Sectigo TLS expires 2026-10-23 (~54 days) |
| gwinnettcounty.com | Java; DigiCert TLS expires 2026-12-04; HTTP→HTTPS not confirmed on probed hosts |
| gema.georgia.gov | Drupal 10 (latest Drupal is 11.x); Google Trust TLS expires 2026-11-11 |
| gta.georgia.gov | Drupal 10 (same pattern); Google Trust TLS expires 2026-11-11 |
Point-in-time only. A live CivicPlus homepage does not mean back-office networks are restored.
Blacklist and lookalike domains
Email blacklist checks (public DoH, August 30, 2026): norcrossga.net, civicplus.com, gwinnettcounty.com, and gema.georgia.gov were clear on mail/domain lists we can query. GEMA web/CDN IPs showed informational SPFBL notes.
DNS lookalike scans (BEC profile, registered signals only):
| Brand scanned | To review | Likely owned | BEC staging |
|---|---|---|---|
| norcrossga.net | 2 | 0 | 0 |
| civicplus.com | 19 | 0 | 0 |
| gwinnettcounty.com | 10 | 3 | 1 |
High-interest registered names (investigate; not proof this incident used them):
| Lookalike | Technique | Note |
|---|---|---|
| norcrossga.com / norcrossga.org | tld-swap | Live NS + A — not the official .net |
| civic-plus.com / civicpius.com | hyphen / homoglyph | Live NS + MX |
| gwinettcounty.com | omission | BEC staging (NS, MX, no website A) |
| gwinnettcount.com | omission | Live NS + MX |
Type norcrossga.net, not .com. Continuous monitoring: Cybersquat Domain Monitoring.
Related coverage
- Surfside Beach municipal BEC
- Minnesota water-utility OT incident
- Ransomware threat landscape
- Government / education AG breach tracker
- MFA support directory
- U.S. Bank / LockBit claim (leak-site claim — different framing)
Run a free audit at audit.emailmenow.com or contact EmailMeNow for municipal DMARC / MTA-STS and phishing response aimed at the 100% ideal.
Sources: City of Norcross — Cybersecurity Incident · August council recap · FOX 5 Atlanta, Aug 28, 2026 · Hoodline, Aug 29, 2026 · WSB-TV, Aug 29, 2026 · GEMA/HS incident reporting · GTA — HB 156 · O.C.G.A. § 38-3-22.2 · O.C.G.A. § 10-1-912 · CivicPlus 2FA. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches August 30, 2026. Domain scores: audit.emailmenow.com only.