Educational & easy-to consume visual guides to understanding attacks & enhancing resilience
In May 2024, the American Radio Relay League (ARRL), a prominent organisation in the amateur radio community, experienced a sophisticated ransomware attack that significantly disrupted its operations. The cybercriminals infiltrated ARRL's network, compromising various systems and both Windows and Linux servers. This breach led to the encryption of critical data, rendering essential services like the Logbook of The World (LoTW) inaccessible to users. The Federal Bureau of Investigation (FBI) categorised the attack as "unique," highlighting its advanced nature and the extensive impact on ARRL's infrastructure.
Faced with exorbitant ransom demands, ARRL engaged in negotiations with the attackers and ultimately agreed to pay a $1 million ransom to obtain the necessary decryption tools for system restoration. This decision, the organisation said, was made after careful consideration, aiming to expedite the recovery process and minimise prolonged service disruptions. Yet, throughout this challenging period, ARRL maintained transparent communication with its members, providing regular updates on the status of affected services and the ongoing recovery efforts.
Find out everything that happened in this ransomware attack in our ARRL Cyber Attack Timeline Documents.
Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.
In May 2024, the American Radio Relay League (ARRL) — the national association for amateur radio in the United States — was hit by a sophisticated ransomware attack that encrypted its systems and disrupted its IT and online services, including email and the Logbook of The World (LoTW). ARRL involved the FBI and external forensic specialists, who described the incident as extensive and categorised it as 'unique', affecting network devices, servers, cloud-based systems and PCs. The attackers, reportedly the Embargo ransomware operation, stole the personal information of around 150 employees, and ARRL ultimately paid a US$1 million ransom to obtain a decryption tool. Recovery took more than a month, making it one of the most disruptive attacks on a US non-profit in 2024.
ARRL has given several closely related dates: a press release referred to a network attack 'on or around 12 May 2024', while the CEO's breach-notification letter said the ransomware incident was detected and stopped 'on or around 14 May 2024', with systems encrypted on the morning of 15 May. ARRL publicly disclosed the incident on 16 May 2024. Its phone system was restored on 31 May, the Logbook of The World returned to service on 1 July, and some systems such as DXCC remained offline into August 2024.
ARRL did not formally attribute the attack to a specific group, describing it as the work of 'a malicious international cyber group'. However, sources told BleepingComputer that the Embargo ransomware operation was behind the incident. The FBI categorised the attack as 'unique', and ARRL said the threat actors appeared to believe the organisation had extensive insurance coverage that would fund a large ransom.
Yes. ARRL confirmed it paid a US$1 million ransom — not to prevent stolen data from being leaked, but to obtain a decryption tool to restore the systems encrypted in the attack. ARRL said the attackers' demands were 'exorbitant' and were weakened by the fact that they did not hold significant compromising data; after tense negotiation, ARRL agreed to the US$1 million figure. The payment and the cost of restoration were largely covered by the organisation's insurance policy.
In a filing with the Office of Maine's Attorney General, ARRL stated that the breach affected around 150 employees. The CEO's notification letter told affected individuals that the impacted data may have contained personal information including their name, address and Social Security number, though ARRL said there was no evidence the information had been misused. Affected individuals were offered 24 months of Kroll identity-monitoring services, including credit monitoring, identity-theft restoration and up to US$1 million in identity-fraud loss reimbursement.
ARRL stressed that it does not store credit card information anywhere on its systems and does not collect Social Security numbers for members. It said its member database contains only largely public information such as name, address and call sign, along with ARRL-specific data like email preferences and membership dates. ARRL also repeatedly stated that Logbook of The World (LoTW) and DXCC user data were secure and unaffected. The confirmed data theft related to employee information rather than member records.
The attack disrupted a wide range of ARRL services, including email, the Logbook of The World (LoTW), the ARRL Learning Center, the DXCC award system, telephone services, and parts of the Volunteer Examiner Coordinator (VEC) and Radiosport award processing. The @arrl.net email forwarding service continued running, though aliases could not be modified, and the QST magazine print edition faced minor delays. ARRL kept several systems offline as a precaution even where the underlying data was reported to be secure.
Recovery took more than a month, with a phased restoration of services. ARRL's phone system returned on 31 May 2024, many membership and licensing services resumed through late May and June, and the Logbook of The World came back online on 1 July 2024, taking around four more days to clear the backlog. Some systems, notably the online DXCC application, remained offline into August 2024 while ARRL rebuilt under new infrastructure guidelines and standards.
ARRL took affected systems offline, secured its network environment, and engaged independent third-party forensic specialists, while involving the FBI and federal law enforcement. It worked under the guidance of cyber-crime attorneys and the authorities, which led it to communicate cautiously and conservatively during the response. ARRL rebuilt affected servers under new infrastructure guidelines and standards, and offered affected individuals 24 months of Kroll identity-monitoring support.
ARRL said the US$1 million ransom payment, together with the cost of restoration, was largely covered by its insurance policy. It also noted that the attackers appeared to assume ARRL held extensive insurance that would fund a multi-million-dollar payment, which shaped their demands. The episode highlighted both the value and the limits of cyber insurance in a ransomware crisis.
Some members felt ARRL should have communicated more openly about the incident as it unfolded. ARRL explained that it was acting on the advice of industry experts, cyber-crime attorneys and the authorities, who directed it to be conservative and cautious with communications while it restored its network. This tension — between transparency and legally guided caution — is common in ransomware response and is a key crisis-communications lesson from the incident.
The ARRL incident shows that even smaller non-profits with limited resources are targets for sophisticated ransomware, and that recovery can take weeks and disrupt core member services. Key lessons include maintaining tested, offline-capable backups to reduce reliance on attacker decryptors, minimising and protecting sensitive employee data, planning crisis communications in advance, understanding exactly what cyber insurance will and will not cover, and rehearsing the response before a crisis. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.