Three Key Takeaways:
- Understanding why mapping systems are a target starts with what they connect to: 911 dispatch, utilities, permitting and public records all depend on GIS data.
- A state-sponsored group used a compromised ArcGIS server as a hidden backdoor for more than a year, proving attackers see mapping software as a way in, not just a mapping tool.
- GIS servers are often public-facing, lightly monitored and patched on a slower cycle than other systems, which makes them attractive entry points that a managed security program can close.
If you manage IT for a city, county or public agency, your GIS platform probably grew up outside the security spotlight. It started as a mapping tool for planners and engineers. Today it feeds 911 dispatch, utility operations, parcel records and emergency management. That shift is the reason why attackers have started paying attention, and why managed cybersecurity services now treat GIS as a tier-one system.
The threat is not hypothetical. Ransomware attacks on government entities worldwide rose 65 percent in the first half of 2025, reaching 208 incidents, with 72 of them targeting United States agencies. Local governments hold sensitive data, run services that cannot go offline and often operate with small IT teams. Mapping systems sit at the intersection of all three.
Getting this wrong is costly. When core systems go down, cities lose payment portals, dispatch support and public trust at the same time. The good news: Most GIS compromises exploit basics like weak passwords and missed patches, which means the fixes are within reach for any local government willing to act.
Why Are Mapping Systems a Target for Cyberattacks?
Mapping systems are a target because they combine high-value data with low-visibility infrastructure. GIS servers store utility layouts, emergency response data and citizen records, they connect to 911 dispatch and public works systems, and they often run public-facing portals that IT teams monitor less closely than email or finance systems. Attackers exploit that gap.
Three characteristics make GIS platforms especially attractive:
- Valuable data. GIS layers map water lines, power infrastructure, fiber routes and critical facilities. That is reconnaissance gold for both criminal and state-sponsored actors.
- Operational leverage. Encrypt or corrupt GIS data and you disrupt dispatch mapping, permitting, assessments and utility work orders in one stroke.
- A soft perimeter. Public map portals mean the server is reachable from the internet, yet GIS often sits outside the patch and monitoring discipline applied to other systems.
In our experience, GIS servers are among the systems most often missing from a local government’s asset inventory during an initial cybersecurity risk assessment. You cannot defend what you have not counted.
What Do Attackers Actually Do Inside a GIS Server?
They rarely announce themselves. The clearest public example came in October 2025, when researchers at ReliaQuest documented how Flax Typhoon, a China-linked state-sponsored group, quietly controlled an organization’s ArcGIS server for more than a year.
The attackers likely got in through a weak administrator password. They then modified a legitimate ArcGIS extension into a web shell, ran commands through the server’s public portal so their traffic would look like normal GIS activity, and even embedded the backdoor in system backups so a restore would reinfect the server. No malware alarms. No ransom note. Just stealthy, persistent access to a trusted government-adjacent system.
That case reframes the risk. A mapping server is not only something attackers might break. It is something they can live inside while they explore everything else on your network. For a small IT team, spotting that kind of abuse without continuous network security monitoring is close to impossible.
How Does a GIS Attack Disrupt 911 and Emergency Response?
Directly. GIS data is an essential component of Next Generation 911, and public safety agencies rely on it to locate callers and route responders. As of 2026, most states are somewhere in the NG911 transition, which means dispatch accuracy increasingly depends on the freshness and integrity of local GIS data.
CISA’s guidance for emergency communications centers identifies ransomware, malware and telephony denial-of-service attacks as common threats to 911 operations. Corrupted or unavailable GIS data adds a quieter failure mode: calls still connect, but location data and routing degrade when responders can least afford it.
The blast radius extends beyond dispatch. When St. Paul, Minnesota, was hit by the Interlock ransomware group in July 2025, the city shut down its systems defensively, the mayor declared a state of emergency and the governor activated the Minnesota National Guard’s cyber unit. After the city refused to pay, the attackers leaked 43 gigabytes of stolen data. Any city that depends on interconnected systems, GIS included, should assume an attack on one will cascade into many.
How Exposed Are Local Governments Right Now?
More than most realize, though the picture is nuanced. Sophos found that 34 percent of state and local government organizations surveyed were hit by ransomware in 2024, actually the lowest rate among sectors surveyed that year. The concerning detail sits underneath: 99 percent of those hit said attackers attempted to compromise their backups during the attack.
That backup statistic matters for GIS specifically. The Flax Typhoon case showed attackers hiding persistence inside backups, and ransomware crews now routinely target backups first, so victims cannot recover without paying. A backup and disaster recovery strategy that never tests restores, or that backs up an already-compromised GIS server, provides false comfort.
Software exposure compounds the problem. In October 2025 Esri released a patch for a critical SQL injection vulnerability affecting ArcGIS Server versions 11.3 through 11.5 and urged administrators to apply it within two weeks. Local governments that don’t have a formal patch process for GIS infrastructure often run months behind on updates like these. The gap between “patch available” and “patch applied” is where attackers operate.
What Should Local Governments Do to Protect GIS Systems?
Treat GIS like the critical infrastructure it is. The core steps:
- Inventory GIS assets. List every ArcGIS server, portal, extension and integration, including who administers each one.
- Fix identity first. Enforce strong unique passwords and multifactor authentication on GIS admin accounts. Weak admin credentials were the likely entry point in the Flax Typhoon compromise.
- Patch on a schedule. Subscribe to Esri security announcements and apply security patches within days, not quarters.
- Segment the network. A public map portal should never share a flat network with dispatch, finance or utility control systems.
- Monitor for abuse of trusted tools. The most dangerous GIS attacks look like normal GIS traffic. Continuous monitoring and endpoint detection catch what signature-based antivirus misses.
- Protect and test backups. Keep immutable offsite copies and test restores regularly, since nearly all government ransomware victims report attempts to compromise their backups.
- Plan the bad day. Fold GIS outage scenarios into your incident response plan, including manual dispatch mapping fallbacks, an area CISA specifically urges emergency communications centers to plan for.
Most small cities and counties cannot staff this in-house, which is where a managed IT partner for local government with 24/7 helpdesk and support and vCIO strategic guidance carries the load.
The Bottom Line on GIS Cybersecurity
Attackers target mapping systems because they are valuable, connected and under-defended. The Flax Typhoon compromise and the 2025 surge in government ransomware both point to the same conclusion: GIS deserves the same security rigor as your finance system and your 911 network, because it touches both.
Closing the gap does not require a bigger government. It requires an inventory, disciplined patching, protected backups and someone watching around the clock. If you want a clear picture of where your GIS and broader environment stand, schedule a conversation with the G6 team. We will help you find the gaps before someone else does.