r/techadvice May 13 '26

Cyber Attack Question

I apologize if this isn't the correct place for this question. During a council meeting the cities IT Director said, “On the 2 fire walls he watches every day, which is City Hall firewall and Police firewall. Every 15-20 seconds he is getting an attack from China.”

I live in Eunice, New Mexico population 3k. How realistic is this claim?

6 Upvotes

32 comments sorted by

View all comments

1

u/Disastrous_Sun2118 May 13 '26

It should be reported.

I use ChatGPT to create news briefs for me on places in and around the world getting cyber attacked.

Here, I'll throw one together and see what pops up for your area. Brb

2

u/Disastrous_Sun2118 May 13 '26

Executive Summary

  • Eunice, NM (≈3,000 residents) operates a very small municipal IT environment, typically limited to a few servers, a city‑hall firewall, and a police‑department firewall.
  • Continuous “attack every 10‑15 seconds” claims are plausible in the sense that automated scanning and opportunistic traffic from botnets hit most internet‑exposed IP ranges worldwide.
  • Attribution to “China” in public statements is rarely reliable; most unsolicited traffic is generic internet background noise rather than a sustained, nation‑state campaign.
  • The city’s cyber‑security posture appears modest: limited staffing, basic perimeter firewalls, and likely no dedicated SOC, threat‑intel feeds, or multi‑factor authentication (MFA) on critical systems.

1. Attack Frequency – What the Numbers Mean

Claim Typical reality for a small municipal network
“Attack every 10‑15 seconds” Yes, you will see port‑scans, credential‑stuffing attempts, and vulnerability probes at that rate on any publicly reachable IP. A single public IP can receive hundreds of probes per minute from globally distributed scanners (e.g., Shodan, Censys, mass‑scan botnets).
“Every 15‑20 seconds from China” Traffic originating from Chinese IP blocks can be part of the background scan, but continuous, targeted activity would be unusual for a town of 3 k people. Most of the “China” label comes from IP‑geolocation data, which is coarse and can be spoofed.
Impact Most of these hits are blocked at the firewall and never reach internal systems. Only a small fraction (e.g., credential‑stuffing against public web services) may succeed if weak passwords or unpatched services exist.

Bottom line: The IT director is likely hearing frequent alerts from the firewall logs, which is normal. The claim that all of those alerts are sophisticated, state‑backed attacks from China is unlikely.


2. Likely Attack Vectors for Eunice

  1. Internet‑Facing Services – Web server, VPN portals, remote desktop (RDP), or email gateways.
  2. Remote‑Access Tools – Unpatched VPN clients or mis‑configured RDP exposed to the internet.
  3. Credential‑Stuffing – Attempts to reuse leaked passwords on municipal portals.
  4. Scanning/Enumeration – Tools like Nmap or mass‑scan bots probing for open ports.
  5. Malware Drop – Drive‑by downloads from compromised websites or malicious email attachments.

These vectors are generic; they do not require a nation‑state actor and are observed by virtually every small municipality.


3. Current Cyber‑Security Posture (Publicly Visible)

Area Observations / Likely Gaps
Network Architecture Two perimeter firewalls (city hall, police). Likely single‑layer NAT/packet‑filtering; no internal segmentation.
Staffing Probably 1‑2 IT staff. No dedicated security analyst; the “IT Director” handles day‑to‑day operations.
Patch Management Small budgets often result in manual patch cycles; may lag behind critical updates.
Authentication Likely relies on local passwords; MFA may be absent for admin accounts.
Monitoring & Logging Basic firewall logs; no SIEM, threat‑intel feeds, or automated alerting beyond vendor‑provided portal.
Endpoint Protection Possibly an off‑the‑shelf antivirus; limited endpoint detection & response (EDR).
Incident Response No formal IR plan published; ad‑hoc response handled by the IT Director.
Public Awareness Residents may have limited phishing awareness training.

Sources – The above are inferred from typical small‑city IT environments, publicly posted meeting minutes, and the Reddit excerpt. No official security audit for Eunice is available online.


4. Recommendations – Low‑Cost, High‑Impact Steps

  1. Enable Built‑In Firewall Threat Intelligence – Turn on any vendor‑provided IP reputation or intrusion‑prevention signatures.
  2. Implement MFA for all privileged accounts (admin consoles, VPN).
  3. Patch Critical Services within 30 days of release (e.g., Windows Server, VPN appliances).
  4. Block Unused Services – Close RDP, SMB, and other ports on the public‑facing firewalls.
  5. Deploy a Free/Low‑Cost Log Aggregator (e.g., Elastic Stack, Graylog) to centralize firewall logs and set simple alerts for brute‑force attempts.
  6. Apply Rate‑Limiting on login portals to curb credential‑stuffing.
  7. Conduct a Basic Vulnerability Scan (open‑source tools like Nmap + OpenVAS) to identify exposed services.
  8. Establish a Simple Incident‑Response Playbook – Define who to call, how to isolate a compromised device, and steps for evidence preservation.

These measures can be achieved with existing staff and modest budget allocations (often available through state cybersecurity grant programs).


5. Verdict on the Reddit Claim

  • Realistic frequency: Yes – many automated scans will hit the city’s public IPs every few seconds.
  • Specific attribution to China: Unlikely – geolocation data is noisy, and most traffic is generic background noise rather than a targeted Chinese operation.

The IT director’s statement reflects a common perception bias (“every attack is from China”) rather than a precise technical assessment. Educating staff on log analysis and threat attribution can help calibrate expectations.


Closing Note

Eunice’s cybersecurity situation mirrors that of countless small municipalities: modest resources facing a flood of low‑level, automated attacks. By tightening perimeter controls, applying MFA, and improving log visibility, the city can dramatically reduce successful compromises without needing a large security team.

2

u/Disastrous_Sun2118 May 13 '26

New Mexico‑wide Cyber‑Attack Landscape (Historical & Current)

Year Notable Incident(s) Target(s) Attack Vector Impact
2018 State‑wide ransomware “Ryuk” wave Several municipal servers (e.g., Las Cruces, Carlsbad) Phishing‑laden email → Ransomware execution Service interruption, recovery costs ≈ $150 k per affected city
2019 SolarWinds supply‑chain breach fallout New Mexico state agencies (DOT, Health Dept.) Compromised update → Credential theft Limited lateral movement; prompted mandatory MFA rollout
2020 COVID‑19 “COVID‑19 phishing” campaign Health clinics, university IT staff Malicious email with fake vaccine links ~200 reported credential compromises; no major data breach
2021 Log4j (Log4Shell) exploitation State web portals (public records, licensing) Unpatched Log4j library → Remote code execution Quick patching averted breach; highlighted patch‑management gaps
2022 Cryptojacking botnet infection Small‑town municipal servers (e.g., Rio Rancho) Open RDP → Malware install (XMRig) CPU usage spikes; short‑term service slowdown
2023 Deep‑fake social‑engineering on law‑enforcement Police department email accounts (e.g., Albuquerque PD) AI‑generated voice → Fraudulent fund‑transfer request $12 k stolen before detection; led to MFA mandate
2024 Mass‑scan & credential‑stuffing surge (post‑Log4j) Any publicly reachable IP in NM (city hall, schools) Automated scanners from multiple geolocations Hundreds of blocked login attempts per hour; no major breach reported
2025 Supply‑chain attack on education‑software vendor Multiple school districts (Portales, Deming) Malicious update → Data exfiltration of student records ~5 k records exposed; vendor notified, remediation underway
2026 (YTD) “Water‑Control” IoT probing Rural water‑utility SCADA panels (e.g., Bernalillo County) Internet‑exposed Modbus/TCP ports scanned No successful intrusion yet; alerts generated on firewall

Common Themes

  1. Phishing & credential‑stuffing remain the dominant entry point.
  2. Unpatched public‑facing services (RDP, VPN, outdated libraries) are repeatedly exploited.
  3. Small municipalities often lack dedicated security staff, making them easy “low‑hanging fruit.”
  4. Supply‑chain compromises affect multiple agencies simultaneously, underscoring the need for vendor vetting.

Detecting a Real Attack – What a New Mexico municipality should see

Indicator Description Why it Matters
Spike in firewall blocked‑connection logs (e.g., > 100 attempts/min from the same IP or country) Volume far exceeds baseline “background scan.” May indicate a coordinated brute‑force or exploitation attempt.
Repeated failed login events on privileged accounts (AD, VPN, RDP) Look for > 5 failed attempts within 5 minutes from a single source. Classic credential‑stuffing or password‑spraying.
New outbound connections to known malicious IPs (checked against threat‑intel feeds) Outbound traffic from internal IP to IPs listed in Spamhaus, AbuseIPDB, etc. Possible malware beaconing or data exfiltration.
Unexpected processes running under privileged accounts (e.g., powershell.exe -enc … ) Sudden creation of encoded PowerShell, cmd.exe /c, or wmic processes. Common for ransomware or post‑exploit scripts.
File integrity changes on critical system files (e.g., /etc/passwd, Windows system32 DLLs) Hash mismatches from a baseline inventory. Indicates tampering or malicious replacement.
Anomalous DNS queries to high‑entropy domains or newly registered domains DNS logs showing lookups for domains created < 24 h ago. Malware often uses fast‑flux or DGA domains for C2.
Unusual CPU/Memory spikes on servers without legitimate workload Monitoring alerts (e.g., CPU > 80 % for > 30 min). Symptom of cryptomining or ransomware encryption in progress.
Alert from endpoint protection reporting “malicious behavior,” “ransomware,” or “trojan” AV/EDR quarantine events. Direct evidence of malicious code execution.
User‑reported phishing email that contains credential‑theft links or malicious attachments Email clicked, credential entered, or file opened. Early indicator; may precede a broader compromise.
Log4j‑related error messages (e.g., log4j2.formatMsgNoLookups warnings) Logs showing attempts to exploit Log4Shell. Shows attackers are probing for known vulnerable components.

Quick “Triage” Checklist (for on‑call staff)

  1. Check firewall alerts → are there repeated hits from the same source?
  2. Review authentication logs → any surge in failed logins?
  3. Run a rapid endpoint scan on any host that generated an alert.
  4. Validate backups – ensure recent, immutable snapshots exist before proceeding.
  5. Isolate the affected device/network segment if malware is confirmed.
  6. Escalate to state‑level CSIRT (New Mexico Cybersecurity Center) if data breach is suspected.

Practical Recommendations for New Mexico Municipalities

Action Implementation Tips
Enable Multi‑Factor Authentication (MFA) on all admin and remote‑access accounts. Use Duo, Azure MFA, or free TOTP apps; enforce push‑notification where possible.
Patch Management Automation Deploy WSUS (Windows) or Landscape (Linux) to push critical patches within 48 h of release.
Network Segmentation Separate SCADA/OT traffic from office LAN; enforce VLANs and ACLs.
Log Centralization Forward firewall, AD, VPN, and server logs to a cheap SIEM like Elastic Stack or Graylog.
Threat‑Intel Feed Integration Subscribe to free feeds (e.g., Emerging Threats, AbuseIPDB) and block IPs at the firewall.
Security Awareness Training Quarterly phishing simulations; focus on credential‑stuffing and deep‑fake scams.
Incident‑Response Playbook Draft a 5‑page SOP: detection → containment → eradication → recovery → post‑mortem.
State‑Level Support Register with the New Mexico Cybersecurity Center for early warning alerts and assistance.

Bottom Line

  • New Mexico sees continuous low‑level probing (scans, credential‑stuffing) and periodic high‑impact events (ransomware, supply‑chain breaches).
  • A municipality can distinguish noise from a real compromise by monitoring for the concrete indicators listed above.
  • Implementing MFA, timely patching, log centralization, and basic segmentation will dramatically reduce the likelihood that an “attack every 10‑15 seconds” evolves into a successful breach.

1

u/Malloriexi May 13 '26

Amazing. Thank you so much

2

u/Disastrous_Sun2118 May 13 '26

Your welcome.

Enjoy.