Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Fraud topic

No spam. Unsubscribe anytime.

City clerk says ACH payment was made to fraudulent invoice; council approves outside cyber investigation

City Council · July 16, 2024
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

At a July 16 special meeting the city clerk reported an invoice fraud that led to an ACH transfer; the council approved an engagement letter so outside counsel can investigate and staff will pursue IT security improvements. The city's insurer anticipates covering losses subject to a $10,000 deductible.

The city clerk told the council on July 16 that a fraudulent invoice email, purporting to come from contractor HR Green, prompted an ACH transfer for roughly $27,000 and related amounts for engineering fees.

The clerk said the invoice arrived in late June and that a scheduled ACH payment was set up through the city's online banking on the 9th. Early on the 11th the clerk said they had a “gut feeling,” contacted Colleen at HR Green, and learned the email was not sent by that firm. The clerk reported notifying the mayor, the bank, the city's insurance carrier (IAP) and the Johnson County sheriff's office.

Why it matters: the council approved an engagement letter so McDonald Hopkins can begin a forensic investigation; IAP will pay McDonald Hopkins’ fees but the city faces a $10,000 cyber-crime deductible. The council also discussed hiring a professional IT firm to harden the city's systems and avoid future incidents.

The clerk described steps taken after discovering the fraud: changing the city email password (which had not been changed since 2019, the clerk said), scanning computers with the city's current anti-virus, and contacting the bank to ask whether funds could be recovered. The clerk said the bank indicated the funds were likely gone and recovery was unlikely.

On insurance, the clerk said IAP's initial assessment treats the incident as a crime claim with a $1,000 limit and a $10,000 deductible. If the investigation determines the city suffered a systems breach, the claim could be processed under a cyber-crime policy with a larger limit (the clerk cited a $250,000 limit mentioned by IAP) but the same $10,000 deductible. The clerk said, “we will be out $10,000,” and later added, “I will never pay another one,” describing a commitment to change payment practices.

The clerk told council members that IAP will source McDonald Hopkins to conduct the investigation and that McDonald Hopkins requested written approval to proceed. The clerk said they had already spoken with a representative of IAP, who described similar incidents handled elsewhere and advised prompt engagement of outside counsel. The clerk estimated the investigation could take about three to four weeks and said the county detective or federal authorities could become involved if investigators determine the scheme crosses state lines.

Council action: the clerk asked the council to approve and allow the clerk to sign the engagement letter so McDonald Hopkins may begin the investigation. A council member moved and the council voted to permit the clerk to sign the letter; the motion carried with no opposition recorded in the transcript. The clerk noted that McDonald Hopkins’ work would be paid by IAP and that timely approval was needed to avoid delays.

Next steps: staff will work to engage McDonald Hopkins, continue to liaise with IAP and the sheriff's office, and bring options for hiring a professional IT firm to a future meeting. The clerk said staff will also coordinate further with the bank and insurance carrier about recovery and coverage.

The special meeting adjourned at about 6:13 p.m.