Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Council briefed on ongoing cyberattack investigation; authorizes contract changes to allow CJIS review and enters executive session

2217272 · February 4, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

City officials updated Columbus City Council on an ongoing cyber incident, told council that limited protected health and criminal justice data may have been affected, and won approval to modify outside counsel contracts to allow CJIS certification. Council then entered executive session to consult with attorneys.

Columbus City Council received an update on an ongoing cyber incident during its Feb. 3 meeting and approved a contract modification that allows outside counsel and cybersecurity partners to be certified to review Criminal Justice Information Services (CJIS) data as part of the investigation.

A city technology official reported that the city’s remediation work has restored most systems and that the investigation continues. “As of last Friday, the vast majority of our systems have been remediated, 94% with just 24 remaining,” the director told council. The city also said it has identified a small amount of protected health information (PHI) in one database associated with the Division of Fire, estimated to affect fewer than 1,000 individuals; a very small number of those records included Social Security numbers.

The city said there is no evidence to date of misuse of the exposed personal information. Affected individuals in the fire database will receive mailed notices and are eligible for two years of Experian credit and dark‑web monitoring. Columbus is offering the monitoring service to any resident who shared information with the city; enrollment details are posted at columbus.gov/cyber.

City Attorney Laura Baker Morris explained that, because some breached data might constitute CJIS information by law, outside counsel and contracted cybersecurity experts need state certification to review CJIS. Council passed ordinance 0297‑2025 to authorize contract amendments that include an FBI CJIS security addendum so those outside parties can proceed with certified review. The ordinance passed on a committee roll call.

After the public update and passage of the CJIS authorization, Council voted to go into executive session under Columbus City Charter Section 8 and Ohio Revised Code Section 121.22(G)(3) to confer with the city attorney and outside counsel about the matter. The roll call for the executive session recorded unanimous agreement to enter the closed session. Council members stated that no formal action would be taken during executive session and that any votes would be recorded in public after the session concluded.

Councilors emphasized that litigation and the active nature of the investigation constrain what can be discussed in public. A council member who chaired the Finance and Governance Committee said the council remains engaged in oversight despite those limits and will continue to review the administration’s response.

City officials said the investigation is ongoing and that the city is cooperating with law enforcement. The city reported that roughly 22,173 individuals had enrolled in Experian identity protection services provided by the city, and reiterated that the investigation will take time to complete.