Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Richland County officials outline response after large county data breach; residents report confusing notification letters
Summary
County officials said outside cybersecurity specialists and legal counsel investigated a months-long breach; insurance covered investigation costs beyond a $10,000 deductible. Residents reported receiving inconsistent letters and asked for clearer help enrolling in credit monitoring and identity-protection services.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Richland County officials told residents at a public board meeting that the county engaged outside cybersecurity specialists and legal counsel to investigate a months-long data breach and has followed experts’ recommendations for notification and remediation.
County Administrator Pesh said the county worked “every step of the way” with legal and cybersecurity teams and that some technical details cannot be disclosed in an open forum because “there are things that we cannot discuss publicly…vulnerabilities that could be created by having some of those discussions.” Pesh told residents a handout of frequently asked questions was distributed and that the county would answer questions to the extent permitted by its security advisers.
Residents said they received multiple and sometimes inconsistent notification letters. Suzanne Fish said she received three letters with different name/address combinations and asked how that happened; Pesh said the vendor’s data-matching produced imperfect results and the vendor “over-notified” to try to reach anyone who might have been affected. The county advised residents who received letters not applicable to them to dispose of the letters or return them to county staff for follow-up.
On the scope of the breach, Pesh said investigators reached only “possible” conclusions about which county systems were affected and that the county cannot yet publish a definitive department-by-department list because the forensics firm retained certain details for security reasons. Pesh said some banking and medical categories were listed in the notification letters as potentially involved, but that does not mean every listed data element was accessed for every person.
Asked whether law enforcement and federal authorities were involved, officials said law enforcement was notified; the FBI was not engaged in the county-led public update. Pesh said the cyber response team had escalated matters to law enforcement as needed but that details about attribution (foreign or domestic) would not be discussed in an open session.
On cost, the county said its cyber insurance covered most investigation and remediation expenses; the county’s out-of-pocket expense for the incident was the insurance deductible ($10,000), and the board has invested additional funds in new security measures following the incident.
Several residents asked for more practical assistance: help enrolling in credit monitoring, clearer phone support, and in-person help stations. County staff said they are assisting callers and residents in person when requested and are pressing the vendor to improve call-center response times. Officials encouraged residents to place fraud alerts or credit freezes through the credit bureaus and to contact county staff for help scheduling appointments if they need assistance.
The county said it has monitored for any misuse of data and, to date, had not detected nefarious use of the information identified by the forensic team, but officials urged residents to remain vigilant and use available monitoring and fraud-protection steps.
Next steps: county staff said they will continue to work with the cyber response firm, law enforcement and the insurer, will improve local assistance and communications, and will implement additional security measures recommended by the investigators.

