The Georgia Superior Court Clerks' Cooperative Authority (GSCCCA), which manages real estate, civil court filings, and other critical records for all 159 counties in Georgia, suffered a significant cyberattack attributed to the ransomware group Devman. The incident forced the GSCCCA to shut down its website and services, initially citing maintenance before confirming a credible and ongoing cybersecurity threat. The organization has since restricted access to its systems and is conducting extensive testing to ensure safety before restoring operations, warning of continued outages across the state.
Devman claimed responsibility for the attack, listing GSCCCA on its leak site and alleging the theft of 500 GB of sensitive data. The group is demanding a $400,000 ransom, with a deadline set for November 27. The GSCCCA holds extensive data, including real estate deeds, property filings, mortgage records, and legal archives, raising concerns about the potential impact of the breach. The attack follows a recent trend of ransomware targeting government and critical infrastructure organizations, with Devman previously linked to other high-profile incidents.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
GSCCCA publicly reported a credible and ongoing cybersecurity threat and said staff were working around the clock to test and analyze systems before restoring access. The agency warned that service disruptions could continue while validation efforts were underway.
After the disruption began, Devman added GSCCCA to its leak site, claiming it stole 500 GB of data and demanding $400,000. The group set a payment deadline of November 27, 2025.
On Friday, the Georgia Superior Court Clerks' Cooperative Authority said a cyberattack began and it immediately restricted access to its website and services, causing statewide outages. The organization initially framed the disruption as maintenance before confirming an active cybersecurity threat.
The Devman ransomware group emerged as a new operation in April 2025. Later reporting identified it as the group claiming responsibility for the GSCCCA incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.