Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Fraud topic
No spam. Unsubscribe anytime.
City discloses vendor-account compromise and redirected payment; investigation ongoing
Summary
Finance Director said a single vendor account in the city's Munis system was accessed by an unauthorized user who changed banking details, causing a valid payment to be sent to an account that did not belong to the vendor; the city reported the incident to law enforcement and banking partners and is implementing additional controls.
Get email alerts on the Cybersecurity Fraud topic
No spam. Unsubscribe anytime.
The Finance Committee on May 27 heard from Finance Director Oster about a vendor-account compromise in the city’s Munis financial system that resulted in a valid payment being redirected to a bank account that did not belong to the vendor.
“A vendor account in our Munis system appears to have been compromised by a bad actor,” Director Oster told the committee. He said the bad actor logged in using a valid user ID and password and made unauthorized changes to one vendor’s banking information before the city processed a legitimate invoice. “We don't know how the bad actor obtained that login information at this point,” Oster said.
Oster said only one vendor is known to be impacted so far. The city promptly reported the incident to the governing body, the FBI Internet Crime Complaint Center, the Santa Fe Police Department, the New Mexico State Auditor and the city’s fiscal agent bank. He described the city's response as both technical and procedural: IT and finance staff have implemented additional business-process controls to verify vendor-account changes, are evaluating multi-factor authentication and new cybersecurity tools, and are working with law enforcement and the bank to attempt to recover funds.
“The incident was reported promptly to the governing body, the FBI Internet Crime Complaint Center, the Santa Fe Police Department, the New Mexico State Auditor, and the Fiscal Agent Bank,” Oster said. He warned the recovery process is slow: “This is a slow process, and it may take up to 90 days before we have more information.”
Oster said the city is taking the event “very seriously” and that finance and IT staff had been working around the clock since discovery. He declined to provide operational specifics about newly implemented controls in the public meeting so as not to enable circumvention of the protections.
No formal committee action was taken; the item was presented as a staff report and an ongoing criminal and civil investigation. Staff said work to evaluate additional authentication measures and new cybersecurity tools is underway and that business-process changes to verify vendor-account changes have already been implemented.

