Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Shenandoah: city notifies employees after December cyber intrusion; city says residents' financial data not stored locally
Summary
At the June 26 council meeting Shenandoah's City Attorney announced a December 2023 cyber incident that may have exposed some employee and former-employee files, said less than 1% of data was lost, and reassured residents that Social Security numbers and payment-card data for residents are not maintained by the city.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
The City Attorney told the Shenandoah City Council on June 26 that the city experienced a cyber intrusion on or around Dec. 23–26, 2023. Staff said the city's defenses were successful in stopping the attack and that "less than 1% of the city's data" was lost or accessed.
The prepared public notice read at the meeting said outside cybersecurity professionals were retained to investigate and that certain files containing employee and past-employee information "may have been accessed and acquired by the unauthorized party." The city said it does not maintain Social Security numbers, bank account or credit-card information for residents and that residents' online bill-pay information is handled by PCI-compliant third parties.
City staff said potentially affected individuals with a known mailing address were being notified by U.S. mail; the notice and a press release were scheduled to be published on the city's website and released to the press the following day.
In council discussion, the City Attorney clarified that the earlier-cited figure of roughly 450 records referred to employees and former employees (including past council members who were paid by the city), and not resident records. Several council members publicly thanked the city's IT manager, Chris, for work responding to the incident.
Why it matters: Even when resident financial data are handled by third parties, municipal cyber incidents that expose city employees' records can create privacy and administrative burdens; notices and remediation steps are standard practice. The city indicated it has upgraded defenses and is providing notifications to those whose information may have been affected.
Quotes: "The city's defensive mechanisms were successful in stopping the attack with the loss of less than 1% of the city's data," the City Attorney read. "The city does not maintain Social Security numbers, bank account or credit card information on residents," the notice said.

