Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Athens officials outline recovery, indictments and security fixes after $722,000 cyber theft
Summary
City officials said about $722,000 was stolen from fire-station bond funds in November 2024; investigators froze a portion of that money, federal prosecutors in Iowa have indicted two people, and the city has implemented hardware replacement, expanded multifactor authentication and staff training.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Service Safety Director Andy Stone told reporters that the city of Athens was the victim of a cyber theft in November 2024 that the city reported at about $721,976.26 and that investigators have since recovered and frozen a portion of those funds.
Stone said the city filed a John-and-Jane-Doe civil lawsuit within days of discovering the theft to obtain subpoenas for banking records. He told reporters that investigators were able to freeze roughly $349,522 in a target account and that mediation among the two identified victims and the bank resulted in a negotiated division of the frozen funds. Stone said the city also secured funds from insurance and mediation and credited City Treasurer Josh Thomas for investment activity that returned additional money to the fire station project fund.
"Speed was of the essence to stop any further transfer and laundering," Stone said, describing the quick civil and investigative steps that led to early recoveries. He also said the city filed an IC3 report with the FBI, worked with the Athens police investigations team and retained outside counsel.
Stone described parallel criminal developments: the FBIs Iowa City field office notified local investigators that its probe appeared to link Athenss case to other cybercrime activity. An indictment was filed in the U.S. District Court for the Southern District of Iowa naming two defendants; Stone said the indicted individuals were U.S.-based and until their arrests had been active-duty Air Force members stationed at Dover Air Force Base. He said the city is not a named victim in that indictment but that the FBI informed Athens it could be added as an additional victim during sentencing and any restitution order.
On technical findings and safeguards, Stone said the city completed three cyber forensics reviews (an internal review, a contractor review, and an independent firm engaged via insurance). "Although each investigation came to the same conclusion that the intrusion likely did not occur through any city-owned or controlled system, they each provided suggestions to improve our cyber security environment," he said. Measures the city has implemented, Stone said, include replacing aging hardware and servers, instituting multifactor authentication for all staff, expanded phishing awareness training and additional internal controls from the city auditors office.
In question-and-answer exchanges, Stone told reporters the fire station project was funded with bond proceeds serviced by a public-safety levy and that, in his view, the theft and subsequent cost increases would not directly change the proposed city income tax ballot measure. He said recovered funds and the bondinvestment gains would go back into the public safety capital (206) fund and that any future spending from that fund requires a council appropriation.
Stone and other officials urged residents to report scams and suspicious activity promptly. "When we get involved, we usually catch it pretty early," Stone said, and he emphasized the importance of examining email addresses, avoiding clicking unfamiliar links and reporting suspected fraud so investigators can link related cases.
When asked about the federal case, Stone read the federal case number (reported as 1:25-mj-00634-NA) and reiterated the indictment is filed in the Southern District of Iowa; he said the city had not received a recent status update but that investigators had been told the city could be added as a victim for restitution at sentencing.
On the intrusion method, Stone described a business-email-compromise pattern and "domain masking," in which attackers retroactively altered message signatures and addresses to make fraudulent domains appear to have been part of legitimate chains. He said one fraudulent domain was created around Oct. 20, 2024, with direct malicious communications beginning around Nov. 18, 2024, and that a second domain appeared after the money was moved.
Stone said the city will continue civil recovery efforts in coordination with its insurer and counsel and that additional indictments or state-level charges remain possible as investigations continue. The city said it has been in touch with the Ohio Auditor of State and has shared lessons learned for other political subdivisions.
The briefing ended with Stone offering copies of his prepared statement to the press and inviting follow-up questions.

