Cyber-Attack Timeline: ARRL

Educational & easy-to consume visual guides to understanding attacks & enhancing resilience

ARRL Timeline Image ARRL Summary Image

Download Our Educational Cyber-Attack Timeline: ARRL

In May 2024, the American Radio Relay League (ARRL), a prominent organisation in the amateur radio community, experienced a sophisticated ransomware attack that significantly disrupted its operations. The cybercriminals infiltrated ARRL's network, compromising various systems and both Windows and Linux servers. This breach led to the encryption of critical data, rendering essential services like the Logbook of The World (LoTW) inaccessible to users. The Federal Bureau of Investigation (FBI) categorised the attack as "unique," highlighting its advanced nature and the extensive impact on ARRL's infrastructure. ​

Faced with exorbitant ransom demands, ARRL engaged in negotiations with the attackers and ultimately agreed to pay a $1 million ransom to obtain the necessary decryption tools for system restoration. This decision, the organisation said, was made after careful consideration, aiming to expedite the recovery process and minimise prolonged service disruptions. Yet, throughout this challenging period, ARRL maintained transparent communication with its members, providing regular updates on the status of affected services and the ongoing recovery efforts.

Find out everything that happened in this ransomware attack in our ARRL Cyber Attack Timeline Documents.  

Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.

  • ** GDPR ** We wholeheartedly believe your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data. 
  • Align with the GDPR requirements.
  • Increase your Breach Readiness.
  • Reduce your time to detect and respond.

Complete the form below to receive a copy of the detailed ARRL Attack timeline document and summary.

cyber-essentials-certification
NCSC Certified Training B&W 300px
CSC

FAQs on the ARRL Cyber Attack

  • 1. What happened in the ARRL cyber attack?

    In May 2024, the American Radio Relay League (ARRL) — the national association for amateur radio in the United States — was hit by a sophisticated ransomware attack that encrypted its systems and disrupted its IT and online services, including email and the Logbook of The World (LoTW). ARRL involved the FBI and external forensic specialists, who described the incident as extensive and categorised it as 'unique', affecting network devices, servers, cloud-based systems and PCs. The attackers, reportedly the Embargo ransomware operation, stole the personal information of around 150 employees, and ARRL ultimately paid a US$1 million ransom to obtain a decryption tool. Recovery took more than a month, making it one of the most disruptive attacks on a US non-profit in 2024.

  • 2. When did the ARRL cyber attack take place?

    ARRL has given several closely related dates: a press release referred to a network attack 'on or around 12 May 2024', while the CEO's breach-notification letter said the ransomware incident was detected and stopped 'on or around 14 May 2024', with systems encrypted on the morning of 15 May. ARRL publicly disclosed the incident on 16 May 2024. Its phone system was restored on 31 May, the Logbook of The World returned to service on 1 July, and some systems such as DXCC remained offline into August 2024.

  • 3. Who was behind the ARRL cyber attack?

    ARRL did not formally attribute the attack to a specific group, describing it as the work of 'a malicious international cyber group'. However, sources told BleepingComputer that the Embargo ransomware operation was behind the incident. The FBI categorised the attack as 'unique', and ARRL said the threat actors appeared to believe the organisation had extensive insurance coverage that would fund a large ransom.

  • 4. Did ARRL pay a ransom in the cyber attack?

    Yes. ARRL confirmed it paid a US$1 million ransom — not to prevent stolen data from being leaked, but to obtain a decryption tool to restore the systems encrypted in the attack. ARRL said the attackers' demands were 'exorbitant' and were weakened by the fact that they did not hold significant compromising data; after tense negotiation, ARRL agreed to the US$1 million figure. The payment and the cost of restoration were largely covered by the organisation's insurance policy.

  • 5. What data was stolen in the ARRL breach?

    In a filing with the Office of Maine's Attorney General, ARRL stated that the breach affected around 150 employees. The CEO's notification letter told affected individuals that the impacted data may have contained personal information including their name, address and Social Security number, though ARRL said there was no evidence the information had been misused. Affected individuals were offered 24 months of Kroll identity-monitoring services, including credit monitoring, identity-theft restoration and up to US$1 million in identity-fraud loss reimbursement.

  • 6. Was ARRL members' personal data affected?

    ARRL stressed that it does not store credit card information anywhere on its systems and does not collect Social Security numbers for members. It said its member database contains only largely public information such as name, address and call sign, along with ARRL-specific data like email preferences and membership dates. ARRL also repeatedly stated that Logbook of The World (LoTW) and DXCC user data were secure and unaffected. The confirmed data theft related to employee information rather than member records.

  • 7. Which ARRL services were affected by the attack?

    The attack disrupted a wide range of ARRL services, including email, the Logbook of The World (LoTW), the ARRL Learning Center, the DXCC award system, telephone services, and parts of the Volunteer Examiner Coordinator (VEC) and Radiosport award processing. The @arrl.net email forwarding service continued running, though aliases could not be modified, and the QST magazine print edition faced minor delays. ARRL kept several systems offline as a precaution even where the underlying data was reported to be secure.

  • 8. How long was ARRL down and when did it recover?

    Recovery took more than a month, with a phased restoration of services. ARRL's phone system returned on 31 May 2024, many membership and licensing services resumed through late May and June, and the Logbook of The World came back online on 1 July 2024, taking around four more days to clear the backlog. Some systems, notably the online DXCC application, remained offline into August 2024 while ARRL rebuilt under new infrastructure guidelines and standards.

  • 9. How did ARRL respond to the cyber attack?

    ARRL took affected systems offline, secured its network environment, and engaged independent third-party forensic specialists, while involving the FBI and federal law enforcement. It worked under the guidance of cyber-crime attorneys and the authorities, which led it to communicate cautiously and conservatively during the response. ARRL rebuilt affected servers under new infrastructure guidelines and standards, and offered affected individuals 24 months of Kroll identity-monitoring support.

  • 10. Did insurance cover the ARRL ransom payment?

    ARRL said the US$1 million ransom payment, together with the cost of restoration, was largely covered by its insurance policy. It also noted that the attackers appeared to assume ARRL held extensive insurance that would fund a multi-million-dollar payment, which shaped their demands. The episode highlighted both the value and the limits of cyber insurance in a ransomware crisis.

  • 11. Why was ARRL criticised over its communication?

    Some members felt ARRL should have communicated more openly about the incident as it unfolded. ARRL explained that it was acting on the advice of industry experts, cyber-crime attorneys and the authorities, who directed it to be conservative and cautious with communications while it restored its network. This tension — between transparency and legally guided caution — is common in ransomware response and is a key crisis-communications lesson from the incident.

  • 12. What can organisations learn from the ARRL cyber attack?

    The ARRL incident shows that even smaller non-profits with limited resources are targets for sophisticated ransomware, and that recovery can take weeks and disrupt core member services. Key lessons include maintaining tested, offline-capable backups to reduce reliance on attacker decryptors, minimising and protecting sensitive employee data, planning crisis communications in advance, understanding exactly what cyber insurance will and will not cover, and rehearsing the response before a crisis. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.

We are industry experienced practitioners when it comes to cyber security training & cyber security consultancy services

1487652208_graduationcap

Training

We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.

1487652701_like

Virtual CISO Services

Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.

1487652784_calendar-3

Virtual Cyber Assistant

A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.

1487652846_microphone

Cyber Crisis Tabletop Exercises

Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.

1487652632_search

Ransomware Tabletop Exercise

Measure your organisation’s Ransomware Readiness with a unique blend of verbal and visual simulations and ransomware scenario walkthroughs.

1487652567_line-chart

Executive Cyber Awareness Sessions

Specially designed for executive management, CEOs and boards of directors, engaging them in a business context to help explain the threats and risks from cyber-attacks.

How we use your data:

  • The form above collects personal information so we may email you the requested information and pressing the "Get your free copy now"  button acts as informed consent for this processing purpose. Consequently we may be in touch to:

    • Update you when we host our ground-breaking Wisdom of Crowds events in your country or region.
    • Keep you posted on free resources and documents around Wisdom of Crowds events and its outputs. (For example, we tend to create insightful mind maps and we also are the creators of free to view Insights with Cyber Leaders Video Interviews. )
    • Ping you a note about upcoming FREE educational webinars on GDPR and Cybersecurity.
    • Inform you of any upcoming Data Breach Response or Cyber Incident Response training.  
  • Using the information from this page we will NOT sell or market to you any of our consultancy or trusted advisory services.  
  • In its purest interpretation, this act of us communicating with you is direct marketing and is processed on the basis of our legitimate interest and your engaging in our services. All marketing communication will include an unsubscribe button or other method of ending communication.