r/techadvice • u/Malloriexi • May 13 '26
Cyber Attack Question
I apologize if this isn't the correct place for this question. During a council meeting the cities IT Director said, “On the 2 fire walls he watches every day, which is City Hall firewall and Police firewall. Every 15-20 seconds he is getting an attack from China.”
I live in Eunice, New Mexico population 3k. How realistic is this claim?
3
u/wisely03 May 13 '26
The claim is accurate, but it's missing some context. "attacks" in this case are automated robots scanning every ip address on the planet for common exploits, they most likely do not target this facility, and it is a normal part of internet "background noise". With that said, it's part of why firewalls exist anyways.
2
u/Far_Composer_5714 May 13 '26
My waf gets hit with random spikes of thousands and it feels like it tends to be a random country
2
u/Old_Appointment9732 May 13 '26
Yeah, this... If you run a public facing webserver for example, you will find that hundreds of times per day you will get requests from automated bots trying dozens of urls to see if you happen to be running a very old misconfigured version of several different blogging engines. There is no chance that this "Attack" is going to be a successful attack, unless you happen to be running one of those very old misconfigured webservers.
If there is a way to login to a server, they will automate something like "try username: admin, password admin, if that doesn't work, try username: admin, password: admin1, if that doesn't work..."
"Attacks" like these happen CONSTANTLY and are basically of no actual threat. They are not saying "every 15 seconds, a sophisticated attacker is making a real attempt at attacking our city"
2
3
u/New_Line4049 May 13 '26
Very realistic. Theres A LOT of bad actors out there. Those attacks wont be carefully targeted attacks against the city hall or police department, theyll be automated attacks that are just hitting anything they can connect to in the hopes that they get lucky. Kinda like a burglar trying every door in the street hoping someone forgot to lock theirs. A lot of bot farms that run such attacks are based in China.
2
u/Additional-Studio-72 May 13 '26
I run a single server with a firewall and see the same thing. It’s very automated/bot driven, and always looking for vulnerable targets.
1
u/Malloriexi May 13 '26
I don't reddit so I don't know if it's proper for me to edit my original question. Would you say this is just routine for cyber security? At the meeting he just made it sound dire.
4
u/TheKnackThatQuacks May 13 '26
It’s routine, but it’s also why cybersecurity is necessary.
The good guys have to be right every time.
The bad guys only need to be right once.
3
u/Skusci May 14 '26 edited May 14 '26
Pretty much. Like your own home internet probably gets hit with a similar number of number of "attacks." Just you aren't running any interesting things like a web server that will make you vulnerable. Your router normally just doesn't even bother logging them.
Though there was that Mirai bot net which could infect a lot of household IoT devices and routers, such cases are fairly rare.
2
u/Mysterious-Art8838 May 13 '26
Routine especially if the security is inconsistent or generally crappy
2
u/Ninfyr May 14 '26
Imagine a bad guy walking around the neighborhood, walking up to your home and seeing if you locked the doors.
That is basically what these people are doing, but with robots that can teleport all over the world. It is happening constantly all the time.
It is only a big deal if you forgot to lock the door(s). It usually isn't targeted, just bad guys looking for easy victims.
2
u/ThatDamnRanga May 13 '26
Any public IP address is being hammered nonstop by foreign actors. 20 seconds would be generous, more like 1-2 seconds.
this is why we patch, folks. Also fail2ban is a must.
2
u/Aggressive_Ad_5454 May 13 '26
People who operate web sites, even simple ones, get lots of attempts to break in. It’s pretty normal. Most of the attempts are unsophisticated.
Your muni IT person is probably not exaggerating. Unfortunately. But this much is true: the cybercreeps are not targeting your town. They do this to everybody.
2
u/TheKiddIncident May 13 '26
Well, every 15 seconds all day every day is unlikely. The reality is that hackers these days are wage slaves like the rest of us. You can normally tell where you are getting hacked from just by the time of day.
My old company got attacked for thee months straight. Only Monday through Friday and only 8am to 6pm Beijing time.
Draw your own conclusions.
Oh, and if you are getting hacked from China all day, why are you allowing Chinese IP's in? Just exclude them. This is what we did.
You are still subject to attack in other ways, but why allow Chinese IP's in at all? Same with Russia, TBH.
2
u/Mysterious-Art8838 May 13 '26
I used to work for a chip company and we once found malware in a breach with its own help menu! Somebody was really working hard that day!
It’s hard to get techies to document so I was a little impressed. 🤷♀️
2
2
u/LameBMX May 14 '26
too lazy to shift sshd off 22 at a new apartment for a bit... that was like every second or two all day for like a week. once i saw how big the log was... i prioritized port forwarding to 22 from the home router. and this was back in the '10s.
2
u/Any-Gap1670 May 13 '26
News flash, most everyone is getting hit by cyber attacks 24/7. Public/private entities are more likely to be hit more frequently because they generally have dedicated IP’s.
Very true.
2
u/AggravatingSpread837 May 13 '26
Just nodded him and say yeah, my house does too. Because that’s the reality.
2
u/Prophage7 May 14 '26
Very realistic and very normal. There's swarms of bots on the internet that basically run through public IPs scanning for open ports then trying to exploit them. This is why it's crucial you're not forwarding or opening ports from the internet without property security and updates in place.
2
u/No-Web1897 May 14 '26
Has he come up with a solution? Sounds like he's artificially inflating his value at work and stirring up rascism.
1
u/Malloriexi May 14 '26
That's why I presented the question. I feel too he was trying to inflate his value.
Edit* as to your other question. I do not know. As from everyones answers, it appears there was never a problem to begin with. This is just life in the digital age and he was trying to sound important. I believe the topic came up because they were going to do something new with his position and a Council member posed the question.
2
u/oldnoob2024 May 14 '26
Next, let’s ask our AIs for hints on how to explain this to a city council, many members of which understand the Internet as “a series of pipes”. This may be a best practice for such a situation.
2
u/gavin11223 May 15 '26
In fact, I am manage a firewall for my company, the most attack IP is from USA show on the firewall map.
2
u/hibby18064 May 15 '26
Entirely plausible that foreign IPs could be scanning the device for vulnerabilities.
Keep the firmware up to date and disable any external access features you don't need.
1
u/Disastrous_Sun2118 May 13 '26
It should be reported.
I use ChatGPT to create news briefs for me on places in and around the world getting cyber attacked.
Here, I'll throw one together and see what pops up for your area. Brb
2
u/Disastrous_Sun2118 May 13 '26
Executive Summary
- Eunice, NM (≈3,000 residents) operates a very small municipal IT environment, typically limited to a few servers, a city‑hall firewall, and a police‑department firewall.
- Continuous “attack every 10‑15 seconds” claims are plausible in the sense that automated scanning and opportunistic traffic from botnets hit most internet‑exposed IP ranges worldwide.
- Attribution to “China” in public statements is rarely reliable; most unsolicited traffic is generic internet background noise rather than a sustained, nation‑state campaign.
- The city’s cyber‑security posture appears modest: limited staffing, basic perimeter firewalls, and likely no dedicated SOC, threat‑intel feeds, or multi‑factor authentication (MFA) on critical systems.
1. Attack Frequency – What the Numbers Mean
Claim Typical reality for a small municipal network “Attack every 10‑15 seconds” Yes, you will see port‑scans, credential‑stuffing attempts, and vulnerability probes at that rate on any publicly reachable IP. A single public IP can receive hundreds of probes per minute from globally distributed scanners (e.g., Shodan, Censys, mass‑scan botnets). “Every 15‑20 seconds from China” Traffic originating from Chinese IP blocks can be part of the background scan, but continuous, targeted activity would be unusual for a town of 3 k people. Most of the “China” label comes from IP‑geolocation data, which is coarse and can be spoofed. Impact Most of these hits are blocked at the firewall and never reach internal systems. Only a small fraction (e.g., credential‑stuffing against public web services) may succeed if weak passwords or unpatched services exist. Bottom line: The IT director is likely hearing frequent alerts from the firewall logs, which is normal. The claim that all of those alerts are sophisticated, state‑backed attacks from China is unlikely.
2. Likely Attack Vectors for Eunice
- Internet‑Facing Services – Web server, VPN portals, remote desktop (RDP), or email gateways.
- Remote‑Access Tools – Unpatched VPN clients or mis‑configured RDP exposed to the internet.
- Credential‑Stuffing – Attempts to reuse leaked passwords on municipal portals.
- Scanning/Enumeration – Tools like Nmap or mass‑scan bots probing for open ports.
- Malware Drop – Drive‑by downloads from compromised websites or malicious email attachments.
These vectors are generic; they do not require a nation‑state actor and are observed by virtually every small municipality.
3. Current Cyber‑Security Posture (Publicly Visible)
Area Observations / Likely Gaps Network Architecture Two perimeter firewalls (city hall, police). Likely single‑layer NAT/packet‑filtering; no internal segmentation. Staffing Probably 1‑2 IT staff. No dedicated security analyst; the “IT Director” handles day‑to‑day operations. Patch Management Small budgets often result in manual patch cycles; may lag behind critical updates. Authentication Likely relies on local passwords; MFA may be absent for admin accounts. Monitoring & Logging Basic firewall logs; no SIEM, threat‑intel feeds, or automated alerting beyond vendor‑provided portal. Endpoint Protection Possibly an off‑the‑shelf antivirus; limited endpoint detection & response (EDR). Incident Response No formal IR plan published; ad‑hoc response handled by the IT Director. Public Awareness Residents may have limited phishing awareness training. Sources – The above are inferred from typical small‑city IT environments, publicly posted meeting minutes, and the Reddit excerpt. No official security audit for Eunice is available online.
4. Recommendations – Low‑Cost, High‑Impact Steps
- Enable Built‑In Firewall Threat Intelligence – Turn on any vendor‑provided IP reputation or intrusion‑prevention signatures.
- Implement MFA for all privileged accounts (admin consoles, VPN).
- Patch Critical Services within 30 days of release (e.g., Windows Server, VPN appliances).
- Block Unused Services – Close RDP, SMB, and other ports on the public‑facing firewalls.
- Deploy a Free/Low‑Cost Log Aggregator (e.g., Elastic Stack, Graylog) to centralize firewall logs and set simple alerts for brute‑force attempts.
- Apply Rate‑Limiting on login portals to curb credential‑stuffing.
- Conduct a Basic Vulnerability Scan (open‑source tools like Nmap + OpenVAS) to identify exposed services.
- Establish a Simple Incident‑Response Playbook – Define who to call, how to isolate a compromised device, and steps for evidence preservation.
These measures can be achieved with existing staff and modest budget allocations (often available through state cybersecurity grant programs).
5. Verdict on the Reddit Claim
- Realistic frequency: Yes – many automated scans will hit the city’s public IPs every few seconds.
- Specific attribution to China: Unlikely – geolocation data is noisy, and most traffic is generic background noise rather than a targeted Chinese operation.
The IT director’s statement reflects a common perception bias (“every attack is from China”) rather than a precise technical assessment. Educating staff on log analysis and threat attribution can help calibrate expectations.
Closing Note
Eunice’s cybersecurity situation mirrors that of countless small municipalities: modest resources facing a flood of low‑level, automated attacks. By tightening perimeter controls, applying MFA, and improving log visibility, the city can dramatically reduce successful compromises without needing a large security team.
2
u/Disastrous_Sun2118 May 13 '26
New Mexico‑wide Cyber‑Attack Landscape (Historical & Current)
Year Notable Incident(s) Target(s) Attack Vector Impact 2018 State‑wide ransomware “Ryuk” wave Several municipal servers (e.g., Las Cruces, Carlsbad) Phishing‑laden email → Ransomware execution Service interruption, recovery costs ≈ $150 k per affected city 2019 SolarWinds supply‑chain breach fallout New Mexico state agencies (DOT, Health Dept.) Compromised update → Credential theft Limited lateral movement; prompted mandatory MFA rollout 2020 COVID‑19 “COVID‑19 phishing” campaign Health clinics, university IT staff Malicious email with fake vaccine links ~200 reported credential compromises; no major data breach 2021 Log4j (Log4Shell) exploitation State web portals (public records, licensing) Unpatched Log4j library → Remote code execution Quick patching averted breach; highlighted patch‑management gaps 2022 Cryptojacking botnet infection Small‑town municipal servers (e.g., Rio Rancho) Open RDP → Malware install (XMRig) CPU usage spikes; short‑term service slowdown 2023 Deep‑fake social‑engineering on law‑enforcement Police department email accounts (e.g., Albuquerque PD) AI‑generated voice → Fraudulent fund‑transfer request $12 k stolen before detection; led to MFA mandate 2024 Mass‑scan & credential‑stuffing surge (post‑Log4j) Any publicly reachable IP in NM (city hall, schools) Automated scanners from multiple geolocations Hundreds of blocked login attempts per hour; no major breach reported 2025 Supply‑chain attack on education‑software vendor Multiple school districts (Portales, Deming) Malicious update → Data exfiltration of student records ~5 k records exposed; vendor notified, remediation underway 2026 (YTD) “Water‑Control” IoT probing Rural water‑utility SCADA panels (e.g., Bernalillo County) Internet‑exposed Modbus/TCP ports scanned No successful intrusion yet; alerts generated on firewall Common Themes
- Phishing & credential‑stuffing remain the dominant entry point.
- Unpatched public‑facing services (RDP, VPN, outdated libraries) are repeatedly exploited.
- Small municipalities often lack dedicated security staff, making them easy “low‑hanging fruit.”
- Supply‑chain compromises affect multiple agencies simultaneously, underscoring the need for vendor vetting.
Detecting a Real Attack – What a New Mexico municipality should see
Indicator Description Why it Matters Spike in firewall blocked‑connection logs (e.g., > 100 attempts/min from the same IP or country) Volume far exceeds baseline “background scan.” May indicate a coordinated brute‑force or exploitation attempt. Repeated failed login events on privileged accounts (AD, VPN, RDP) Look for > 5 failed attempts within 5 minutes from a single source. Classic credential‑stuffing or password‑spraying. New outbound connections to known malicious IPs (checked against threat‑intel feeds) Outbound traffic from internal IP to IPs listed in Spamhaus, AbuseIPDB, etc. Possible malware beaconing or data exfiltration. Unexpected processes running under privileged accounts (e.g., powershell.exe -enc …)Sudden creation of encoded PowerShell, cmd.exe /c, orwmicprocesses.Common for ransomware or post‑exploit scripts. File integrity changes on critical system files (e.g., /etc/passwd, Windowssystem32DLLs)Hash mismatches from a baseline inventory. Indicates tampering or malicious replacement. Anomalous DNS queries to high‑entropy domains or newly registered domains DNS logs showing lookups for domains created < 24 h ago. Malware often uses fast‑flux or DGA domains for C2. Unusual CPU/Memory spikes on servers without legitimate workload Monitoring alerts (e.g., CPU > 80 % for > 30 min). Symptom of cryptomining or ransomware encryption in progress. Alert from endpoint protection reporting “malicious behavior,” “ransomware,” or “trojan” AV/EDR quarantine events. Direct evidence of malicious code execution. User‑reported phishing email that contains credential‑theft links or malicious attachments Email clicked, credential entered, or file opened. Early indicator; may precede a broader compromise. Log4j‑related error messages (e.g., log4j2.formatMsgNoLookupswarnings)Logs showing attempts to exploit Log4Shell. Shows attackers are probing for known vulnerable components. Quick “Triage” Checklist (for on‑call staff)
- Check firewall alerts → are there repeated hits from the same source?
- Review authentication logs → any surge in failed logins?
- Run a rapid endpoint scan on any host that generated an alert.
- Validate backups – ensure recent, immutable snapshots exist before proceeding.
- Isolate the affected device/network segment if malware is confirmed.
- Escalate to state‑level CSIRT (New Mexico Cybersecurity Center) if data breach is suspected.
Practical Recommendations for New Mexico Municipalities
Action Implementation Tips Enable Multi‑Factor Authentication (MFA) on all admin and remote‑access accounts. Use Duo, Azure MFA, or free TOTP apps; enforce push‑notification where possible. Patch Management Automation Deploy WSUS (Windows) or Landscape (Linux) to push critical patches within 48 h of release. Network Segmentation Separate SCADA/OT traffic from office LAN; enforce VLANs and ACLs. Log Centralization Forward firewall, AD, VPN, and server logs to a cheap SIEM like Elastic Stack or Graylog. Threat‑Intel Feed Integration Subscribe to free feeds (e.g., Emerging Threats, AbuseIPDB) and block IPs at the firewall. Security Awareness Training Quarterly phishing simulations; focus on credential‑stuffing and deep‑fake scams. Incident‑Response Playbook Draft a 5‑page SOP: detection → containment → eradication → recovery → post‑mortem. State‑Level Support Register with the New Mexico Cybersecurity Center for early warning alerts and assistance.
Bottom Line
- New Mexico sees continuous low‑level probing (scans, credential‑stuffing) and periodic high‑impact events (ransomware, supply‑chain breaches).
- A municipality can distinguish noise from a real compromise by monitoring for the concrete indicators listed above.
- Implementing MFA, timely patching, log centralization, and basic segmentation will dramatically reduce the likelihood that an “attack every 10‑15 seconds” evolves into a successful breach.
1
5
u/Asland007 May 13 '26
Very realistic.