Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
County IT warns of fake-invoice scams and urges AI platform policy for staff
Summary
Columbia County IT warned commissioners that fraudsters scrape public notices to send fake invoices from lookalike domains and recommended stronger email monitoring and possible security spending; staff also discussed imposing an approved AI platform to make chatbot use PRA-retrievable.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
County IT staff told Columbia County commissioners on May 11 that fraudsters are "scraping the Internet" for public notices and contractor names, then sending fake invoices from lookalike domains designed to trick vendors into paying or opening malicious attachments.
"They're looking at every public notice generated in every newspaper... They then generate a fake invoice and send it to the contractor from a domain that seems like it might be related to Columbia County," the county IT official said, citing an example domain shown in the meeting: planning-columbiacounty.usa. The official warned that some recipients have paid false invoices and that opening attachments can deposit malicious payloads that steal passwords.
IT staff said technical countermeasures include adding email-previewing for attachments, centralizing IT purchasing and vetting of devices and cables, or investing in subscription network-security services to monitor for malicious activity. The IT official estimated the cost could be "tens of thousands" of dollars and said the increase might be a modest per-department budget impact if the county absorbs new subscriptions or staffing.
Commissioners and staff also discussed artificial-intelligence use by employees and public-records implications. A staff member who attended a recent conference recommended adopting a single approved AI platform that employees log into with their county email so prompts and outputs can be tracked and are subject to public-records requests. "They suggest having a policy and choosing 1 platform that the employees are allowed to use that they log into with their email so we can track it," the staff member said. Participants debated whether draft prompts versus final products should be retrievable under public-records law.
County IT and department leads agreed to explore options for centralized vetting of purchases, additional email protections, and drafting an AI-use policy that balances productivity with public-records obligations. No formal policy was adopted at the work session.
