Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Committee sees overseas traffic spikes on district website; IT staff says scans hit public host, not internal systems
Summary
Committee members noted large international pageviews (including China and Singapore) and an IT staff member said the district’s public site is hosted remotely (Streamline) and likely being scanned by automated scripts; staff said the public site contains no confidential operational links.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Committee members flagged unusual website traffic patterns, including spikes from China and Singapore, and asked staff to investigate whether the traffic represented a security risk. Communications staff said homepage and meeting pages were the most viewed, and noted a surge in views of the emergency-alert page, HQE.
"We had more hits on our website from China last month than we did from America," said Communications staff, describing analytics that showed large international pageviews. The staff member also noted Facebook spikes tied to local interest about water and storm drains.
An IT/Systems staff member told the committee the overseas hits are likely automated scans from bad actors targeting public-facing websites. "This is foreign bad actors potentially scanning networks," the IT/Systems staff member said, explaining that attackers often run publicly available scripts across thousands of sites.
The IT/Systems staff member emphasized the district’s public website is hosted remotely via a vendor (Streamline) and that the hosted page contains only public-facing content. "They're hacking Streamline. They're not hacking us," the staff member said, adding that the public site contains no passwords, internal maps or proprietary controls that would give attackers access to operational systems.
The committee asked communications staff to continue filtering analytics and to investigate anomalous referrers (one report identified trafficcheap.com) so that the district better distinguishes legitimate public interest from automated or suspicious traffic. Staff said the emergency-alert page (HQE) had nearly 3,000 views during a recent peak and that they will monitor and report further findings.
No vulnerability or breach of internal operational systems was reported at the meeting; staff advised continued monitoring and routine cyber-hygiene for publicly hosted content.
