Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Clerk reports email fraud; council authorizes insurer's investigator and discusses IT fixes

Special council · July 16, 2024
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

At a July 16 special council meeting the clerk reported a fraudulent email that led to an unauthorized ACH transfer for an HR Green invoice; the council approved an engagement letter so McDonald Hopkins, retained by the insurer IAP, can investigate and the city will pursue IT security improvements.

At a special council meeting on July 16 the clerk told the council she had been the victim of an email scam that resulted in an unauthorized ACH payment for what appeared to be an HR Green invoice. The clerk said she set up an ACH payment on July 9 after receiving what she later discovered was a fraudulent invoice and that the funds were transferred and could not be recovered by the bank.

The clerk, speaking to the council, said, "I was scammed in an email" and later told members, "there's no getting that back," adding that she had immediately contacted HR Green, the bank, the mayor and the sheriff's department after realizing the problem. According to the clerk, HR Green told her it had not sent the invoice and the city's insurer, IAP, will source an outside law firm to investigate.

Why it matters: the city's cyber-insurance policy includes a $10,000 deductible for cyber crime, which the clerk said the city will likely be responsible for; IAP will pay the investigation fees but a final determination about coverage (and a higher $250,000 coverage line if a system breach is found) depends on the investigator's findings. The clerk told the council that an investigation could take roughly three to four weeks and that the matter might be referred to the FBI if it crosses state lines.

Details presented to the council included the timing and amounts: the clerk said she received a monthly invoice from HR Green on June 26, the fraudulent message arrived later and an ACH transfer was set up on July 9; the invoices on the scam message matched the legitimate invoices line for line except for header details. The clerk said the transaction triggered a bank alert about daily limits when she attempted to process it and that Central State Bank was involved in early recovery efforts but was unable to retrieve the funds.

The clerk asked the council to approve an engagement letter so McDonald Hopkins, the law firm identified by IAP, could proceed with a formal investigation. The clerk said that IAP would cover the firm's fees and requested that the council authorize the mayor or clerk to sign the engagement letter immediately rather than waiting for the next regular meeting. One council member moved to approve the engagement letter, another seconded, and the council approved the authorization by voice vote; the clerk characterized the expected city exposure as the $10,000 deductible.

Council members also discussed immediate IT-security steps. The clerk said the city's email password had not been changed since 2019 and that she ran a scan with the city's provider (South Slope) that showed no detected threats; members agreed the city needs an external IT vendor to audit network settings, clean up devices and advise on ongoing protections so staff are not reliant on internal ad hoc support.

The clerk apologized to the council for the incident and summarized the next steps: notify IAP and HR Green, sign the engagement letter so McDonald Hopkins can begin its work, continue coordination with the sheriff's department, and pursue an IT audit. The council adjourned at about 6:13 p.m.

The motion to authorize the engagement letter carried by voice vote with no opposition recorded; no additional formal actions were taken during the meeting.