Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Fraud Cybersecurity topic

No spam. Unsubscribe anytime.

Clerk reports $27,000 ACH scam; council approves engagement for investigation

City Council · July 16, 2024
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

At a July 16 special City Council meeting the clerk said a spoofed invoice led to an ACH transfer of about $27,000; council voted to approve an engagement letter so insurer-contracted attorneys can investigate. The city’s cyber policy carries a $10,000 deductible.

At a July 16 special City Council meeting the clerk reported the city mistakenly transferred roughly $27,000 by automated clearing house after responding to a spoofed invoice email and said she had approved the payment before realizing it was fraudulent.

The clerk said she received routine invoices from HR Green on June 26 and later received a nearly identical, but fraudulent, email instructing payment by ACH. She said she set up the ACH payment through the city’s online banking on July 9 and realized the email was fraudulent early on July 11 after comparing the messages and contacting Colleen at HR Green, who told the clerk she had not sent the invoice.

“The invoices were line for line exactly the same other than all the stuff at the top,” the clerk said, describing how the spoofed message replicated the original. “I will never pay another one…I will never pay anybody this way again.”

The clerk said she immediately contacted the mayor, the bank and law enforcement; she reported notifying the city’s insurance carrier and filing a report with the Johnson County Sheriff’s Office. She told council the bank indicated the transferred funds were gone and recovery was unlikely.

According to the clerk, the city’s insurer contact (IAP) has arranged for the McDonald Hopkins law firm to lead a forensic and recovery investigation. The clerk said McDonald Hopkins’ fees would be handled through the insurer relationship but that the city’s cyber-crime coverage carries a $10,000 deductible. She said that if investigators determine the incident was caused by a breach of the city’s systems it would shift to a different policy line with a higher limit (described in the meeting as $250,000) but the same $10,000 deductible.

Because council approval and the mayor’s signature were required to retain McDonald Hopkins, the clerk asked the council to allow her to sign the engagement letter so the investigation could proceed without waiting for the next regular meeting. A council member moved and another seconded the request, the council voted by voice and the motion carried.

Council members and the clerk also discussed the city’s IT posture. The clerk said the email account password had not been changed since 2019 and the city currently lacks professional, contracted IT support. Council members agreed the city needs to solicit and hire an IT firm to audit systems, clean up network access and establish ongoing protections.

The clerk said investigators estimate a three- to four-week process for an initial investigation and that the case could be referred to the FBI if it is found to cross state lines. She apologized to council and outlined steps already taken, including changing account passwords and notifying affected vendors.

The council adjourned at approximately 6:13 p.m.