Back to news
Cybersecurity Alert
August 30, 2026 by EmailMeNow IT Consulting

Norcross Confirmed Ransomware on August 1 — Residents Heard Weeks Later

City of Norcross confirmed ransomware on Aug 1, 2026; public notice came late August. Data exposure, actor, and ransom still undisclosed. Audits (ideal 100%): norcrossga.net 60%, gwinnettcounty.com 57%, civicplus.com 43%. CivicPlus: Google Authenticator yes, YubiKey not documented.

Source: City of Norcross · FOX 5 Atlanta · Hoodline

NewsRansomwareLocal GovernmentPhishingMFAYubiKeyAuthenticator AppsCybersecurity
Darkened municipal workstations after a ransomware incident, with a printed notice on the desk

The City of Norcross says it identified a ransomware incident on August 1, 2026 that hit certain computer systems. The official news flash does not name a crew, a ransom, or whether resident or employee records were copied. FOX 5 Atlanta published the city’s media advisory on August 28. Hoodline (Aug 29) is the piece that made the weeks-long gap the headline. WSB-TV repeated the same official facts on Aug 29.

This is not a duplicate of Atlanta 2018 SamSam history, the Surfside Beach municipal BEC, or leak-site claim posts. Norcross confirmed ransomware. It has not confirmed a data breach of personal information. We found no matching leak-site listing and no CourtListener RECAP docket.

Darkened municipal workstations after a ransomware incident, with a printed notice on the desk

Snapshot

FieldDetail
CityNorcross, Gwinnett County, Georgia (norcrossga.net)
IdentifiedAugust 1, 2026 (city news flash)
Public noticeLate August (FOX 5 Aug 28; city CivicAlert AID=2028)
StatusMost systems operational; limited disruptions during restore
Data / actor / ransomNot disclosed
CourtListener0 matching RECAP dockets (Georgia + nationwide, searched Aug 30, 2026)

What the city has said

The official notice is short. Staff engaged cybersecurity professionals and notified law enforcement. Restoration continues. More details later. That is the entire public forensic picture.

Hoodline is right that the calendar gap matters for residents: phishing and “city bill / tax / restore your account” mail can run for weeks while people still think City Hall is fine. Georgia also has two different clocks. O.C.G.A. § 38-3-22.2 (HB 156) requires agencies to report qualifying cyber incidents to GEMA/HS — that portal is not for private citizens. Separately, the Georgia Personal Identity Protection Act (O.C.G.A. § 10-1-912) requires resident notice if unencrypted personal identifying information was acquired. Norcross has not said that threshold was met.

Calendar gap between an August incident date and a later public notice on a municipal desk

The August council recap is easy to over-read. Council approved a ~$62.7 million FY2027 budget (year starts Sept 1). The $23.6 million line is the General Fund, not a cybersecurity earmark. What the city did name is a $48,100 cybersecurity assessment by CyberElite Corporation, paid from a federal cybersecurity grant, after RFP IT 26-10 (proposals due July 7, 2026). That work was already in motion before August 1. It does not prove the city was “just about to get secure.”

What residents and staff should do

  1. Type norcrossga.net and CivicAlert AID=2028 yourself. Do not open “Norcross restore / refund / court reset” mail.
  2. Pay utilities, citations, and taxes only through hosts you typed or apps you already had.
  3. If you get a “your SSN was in the Norcross breach” text, treat it as unverified. The city has not published a resident-data finding.
  4. Municipal peers: report through GEMA/HS. Residents who were actually defrauded use local police and IC3.
  5. Freeze credit if you later receive a named O.C.G.A. § 10-1-912 notice. Do not freeze because a stranger emailed you.

MFA: YubiKey and Google Authenticator

A hardware key does not decrypt a ransomware-locked file server. It does stop a lot of the follow-on phishing that shows up after a city headline: CivicPlus website accounts, vendor logins, and staff mail.

PlatformGradeYubiKeyAuthenticator
CivicPlus accountPassNoYes
Norcross website mailUnevaluatedNot documentedNot documented

CivicPlus (updated July 1, 2026) names Google Authenticator and other TOTP apps for account.civicplus.com. Email one-time codes are the documented fallback. YubiKey / FIDO and account passkeys are not documented. 2FA can be required by the organization; it is not automatically on for every CivicEngage “Website Sign In” resident account.

City mail for norcrossga.net goes to AppRiver (*.arsmtp.com), not a published Microsoft 365 MFA page we can grade. We do not invent a YubiKey path for staff Outlook.

Directory: MFA support directory · Category → Business Apps.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
Proton PassPasskeys + authenticator-style TOTPProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key beside phones showing an authenticator code and an email one-time code

Independent cybersecurity audits

We audited city, county, vendor, and state-program hosts on August 30, 2026. 100% is the idealnone reach it. These scores are public email / transport / website posture. They do not say whether a file server was encrypted.

OrganizationDomainOverallvs 100%
City of Norcrossnorcrossga.net60%−40
Gwinnett Countygwinnettcounty.com57%−43
CivicPluscivicplus.com43%−57
GEMA/HS (program host)gema.georgia.gov29%−71
DomainIdentityTransportWebsite
norcrossga.net50%15%65%
gwinnettcounty.com25%15%87%
civicplus.com25%45%37%
gema.georgia.gov0%15%40%

Audit links: norcrossga.net · gwinnettcounty.com · civicplus.com · gema.georgia.gov

gema.georgia.gov and gta.georgia.gov are georgia.gov program hosts with no MX and Identity 0% — do not treat a 29% score as “GEMA was breached.” The city’s own host is the one residents should type. Both city and county show 15% Transport (MTA-STS / related), which makes spoofed “restoration update” mail easier to deliver.

DNS MX for norcrossga.net (Aug 30, 2026): norcrossga.net.1.0001.arsmtp.com and a secondary hostname orcrossga.net.2.0001.arsmtp.com (missing the n). That is an AppRiver-style label, not proof of a squat. Still: confirm mail paths after a ransomware event.

Domain audit scoreboard versus the 100 percent ideal

Website stack note

Passive website-tech probes on August 30, 2026:

DomainStack signal
norcrossga.netASP.NET (CivicEngage); Let’s Encrypt TLS expires 2026-11-26
civicplus.comStack undetected; Sectigo TLS expires 2026-10-23 (~54 days)
gwinnettcounty.comJava; DigiCert TLS expires 2026-12-04; HTTP→HTTPS not confirmed on probed hosts
gema.georgia.govDrupal 10 (latest Drupal is 11.x); Google Trust TLS expires 2026-11-11
gta.georgia.govDrupal 10 (same pattern); Google Trust TLS expires 2026-11-11

Point-in-time only. A live CivicPlus homepage does not mean back-office networks are restored.

Blacklist and lookalike domains

Email blacklist checks (public DoH, August 30, 2026): norcrossga.net, civicplus.com, gwinnettcounty.com, and gema.georgia.gov were clear on mail/domain lists we can query. GEMA web/CDN IPs showed informational SPFBL notes.

DNS lookalike scans (BEC profile, registered signals only):

Brand scannedTo reviewLikely ownedBEC staging
norcrossga.net200
civicplus.com1900
gwinnettcounty.com1031

High-interest registered names (investigate; not proof this incident used them):

LookalikeTechniqueNote
norcrossga.com / norcrossga.orgtld-swapLive NS + A — not the official .net
civic-plus.com / civicpius.comhyphen / homoglyphLive NS + MX
gwinettcounty.comomissionBEC staging (NS, MX, no website A)
gwinnettcount.comomissionLive NS + MX

Type norcrossga.net, not .com. Continuous monitoring: Cybersquat Domain Monitoring.


Run a free audit at audit.emailmenow.com or contact EmailMeNow for municipal DMARC / MTA-STS and phishing response aimed at the 100% ideal.


Sources: City of Norcross — Cybersecurity Incident · August council recap · FOX 5 Atlanta, Aug 28, 2026 · Hoodline, Aug 29, 2026 · WSB-TV, Aug 29, 2026 · GEMA/HS incident reporting · GTA — HB 156 · O.C.G.A. § 38-3-22.2 · O.C.G.A. § 10-1-912 · CivicPlus 2FA. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches August 30, 2026. Domain scores: audit.emailmenow.com only.