Ransomware and Law Enforcement: Why Police Agencies Keep Getting Hit
Law enforcement agencies are among the most frequently targeted institutions in ransomware campaigns. The reasons are operational, not accidental — and the defensive posture most agencies maintain is inadequate for the threat they face.
By IPA-IAC · 7 min · 19 February 2026

Law enforcement agencies are among the most reliably targeted institutions in ransomware campaigns. The pattern has been consistent for years: a county sheriff’s office goes dark, a metropolitan police department loses access to its records management system, a state criminal justice network encrypts overnight. The incidents are reported, investigated, and then largely forgotten until the next one.
The targeting is not accidental. Ransomware operators have built a detailed picture of which institutions will pay, which ones have defensible networks, and which ones are running infrastructure that makes recovery without payment difficult or impossible. Law enforcement agencies score poorly on all three assessments. Understanding why — and what it means for defensive posture — requires looking at the threat accurately rather than optimistically.
Why Law Enforcement Is a Preferred Target
The operational profile of a law enforcement agency combines several characteristics that ransomware operators find attractive.
Critical operations with low tolerance for downtime. A police department that loses access to its computer-aided dispatch system, records management platform, or warrant database is not a business that can defer operations while it restores from backup. Investigations stall. Officers cannot access arrest records. 911 call handling degrades. The time pressure to restore operations is immediate and severe, which is exactly the pressure that drives ransom payments. Agencies that have consolidated camera feeds, gunshot-detection alerts, and records access into a real-time crime center have an additional single point of failure worth accounting for in incident-response planning, precisely because that consolidation is what makes the capability valuable day to day.
Sensitive data with high extortion value. The double-extortion model — where operators exfiltrate data before encrypting it, then threaten publication — is particularly effective against law enforcement. Agencies hold confidential informant files, undercover officer identities, sealed case materials, juvenile records, sexual assault case files, and investigative intelligence that cannot be disclosed without causing direct harm to individuals and active investigations. Paying to prevent publication is a different calculation than paying to restore operational access, and ransomware operators know it.
Underfunded and understaffed IT security programs. Most county and municipal law enforcement agencies do not have dedicated security operations functions. A single IT administrator covering a department of two hundred officers is not an unusual configuration. The cybersecurity maturity that would make a ransomware intrusion difficult to execute — network segmentation, endpoint detection and response, immutable offline backups, tested incident response plans — is largely absent from agencies that lack both the budget and the personnel to implement it.
CJIS-connected networks with legacy infrastructure. Agencies with access to FBI Criminal Justice Information Services (CJIS) databases — the NCIC, NLETS, and state criminal history repositories — are required to meet the CJIS Security Policy. That policy specifies controls including multi-factor authentication, encryption standards, and audit logging. What it does not mandate is the network architecture and detection capability that would contain a ransomware intrusion once it starts. Compliance with CJIS Security Policy and having a defensible network are not the same thing.
The Threat Actor Landscape
The ransomware groups targeting law enforcement are not a distinct category of attacker — they are the same groups targeting hospitals, school districts, and municipal governments. What makes law enforcement targeting notable is the consistency and the willingness of some operators to continue targeting agencies even when they face additional scrutiny for doing so.
LockBit conducted multiple attacks on law enforcement and criminal justice agencies before its infrastructure was disrupted in 2024. ALPHV/BlackCat targeted the Metropolitan Police Department of the District of Columbia in 2021, exfiltrating personnel files including background investigation records for officers and their family members — among the most sensitive data a police agency holds. Vice Society targeted several police departments as part of a broader pattern of attacks on public sector organizations.
The DC Metropolitan Police attack is worth examining in detail because it illustrates the extortion dynamic clearly. The attackers exfiltrated an estimated 250 gigabytes of data. When MPD did not pay the demanded ransom, ALPHV published intelligence files, disciplinary records, and the personal information of officers and informants. The damage from the data publication was separate from any operational disruption — the sensitive information was disclosed regardless of whether the agency could restore its systems.
CJIS Compliance Does Not Equal Security
A significant misconception in law enforcement IT is that CJIS Security Policy compliance provides meaningful security assurance. It does not.
The CJIS Security Policy establishes a baseline of access controls and configuration requirements for systems that touch criminal justice databases. It requires multi-factor authentication for remote access, defines encryption standards for data in transit and at rest, and specifies audit and accountability controls. These are necessary requirements. They are not sufficient to prevent or contain a ransomware intrusion.
CJIS does not require network segmentation that would isolate a compromised endpoint from critical systems. It does not require endpoint detection and response capability that would identify ransomware behavior before encryption begins. It does not require immutable backup infrastructure that would make recovery possible without paying ransom. Agencies that treat CJIS compliance as the ceiling of their security obligations rather than its floor are operating with a false sense of assurance.
The agencies that have successfully recovered from ransomware intrusions without paying — and there are documented cases — share a common characteristic: they maintained offline, air-gapped backups that ransomware operators could not reach. The investment required to implement and maintain this infrastructure is not large relative to the cost of a ransomware incident. The failure to make that investment consistently is a resource allocation problem, not a technical one.
What Adequate Defensive Posture Looks Like
The gap between CJIS compliance and defensible infrastructure is not bridgeable with a single product purchase. It requires a program.
Network segmentation. The most critical defensive control for containing ransomware is segmentation that prevents lateral movement from a compromised endpoint to critical systems. A records management server should not be reachable from a detective’s workstation unless that connection is specifically authorized and monitored. Most agency networks are flat, which means that a single compromised machine can reach every other system on the network. Segmentation is a project, not a setting, and it requires sustained architectural work to implement and maintain.
Endpoint detection and response (EDR). Signature-based antivirus does not detect ransomware operators during the pre-encryption phase of an intrusion. Modern EDR platforms detect the behavioral indicators of an attack in progress — lateral movement, credential harvesting, large-scale file access — before encryption begins. The difference between detecting an intrusion during the pre-encryption phase and discovering it after encryption is the difference between a containable incident and a catastrophic one.
Immutable backup infrastructure. Ransomware operators routinely target backup systems before initiating encryption. Backups stored on network-attached storage reachable from the primary network will be encrypted along with everything else. Immutable backups — whether maintained on tape, cloud storage with object lock enabled, or truly air-gapped systems — preserve recovery options that operators cannot reach. This is the single defensive control with the highest return on investment for agencies operating under resource constraints.
Tested incident response planning. Most agencies do not have incident response plans. Of those that do, most have never tested them in a tabletop exercise. The chaos that accompanies a ransomware incident in an agency that has never thought through its response — who decides whether to pay, who contacts the FBI, how communications are maintained when email is down, who has the authority to take systems offline — is itself a multiplier of the damage. A half-day tabletop exercise run annually is not a large investment relative to the operational continuity it supports.
The Payment Decision
Law enforcement agencies face a particular version of the payment decision. Paying ransom to criminal groups is, in some cases, illegal under OFAC sanctions — and ransomware operators are increasingly likely to be sanctioned entities. Law enforcement agencies that pay ransom to sanctioned groups face potential Treasury Department liability in addition to the reputational damage of being seen to have funded criminal operations.
The FBI’s position on ransom payment is consistent: do not pay, report the incident through official channels, and work with law enforcement partners on recovery. The practical reality is that agencies facing the immediate loss of critical operational capabilities and the threatened exposure of confidential informant identities make payment decisions under severe pressure that FBI guidance does not fully account for.
The correct answer to this dilemma is to invest in the defensive controls that make payment unnecessary — offline backups, tested recovery procedures, and the network architecture that contains rather than amplifies an intrusion. The investment that would have prevented the payment decision is almost always smaller than the cost of the incident itself. That calculation is the case for treating ransomware preparedness as an operational priority rather than an IT problem.
IPA-IAC covers cybersecurity threats to law enforcement and criminal justice infrastructure in the Threat Intelligence section.