CSIDB logo
Incident

US Virgin Islands Water and Power Authority

Incident posture

Attack window
Oct 2019
Location
U.S. Virgin Islands
Status
Historical
CIA posture
Available to members
Updated
2025-11-02 00:00

Linked entities

Victim
US Virgin Islands Water and Power Authority
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The U.S. Virgin Islands Water and Power Authority experienced a data breach through its Click2Gov payment portal, leading to unauthorized credit and debit card transactions affecting multiple customers. Initial reports of potential compromise prompted an investigation by the software provider, Central Square Technologies, which initially found no evidence of intrusion; however, subsequent fraud incidents confirmed a cyberattack involving a previously unidentified vulnerability. The provider developed and deployed a security patch following the confirmation, though questions remained regarding the attack's novelty and its relationship to prior breaches involving the same payment system.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The U.S. Virgin Islands Water and Power Authority (WAPA) experienced a cybersecurity incident involving its Click2Gov online payment portal, developed by Central Square Technologies (CST). WAPA first identified a potential compromise on October 18, 2019, after which it immediately notified CST of the suspected vulnerability. CST was simultaneously investigating an unconfirmed software issue affecting other clients, including Port Orange, Florida, leading to recommendations to suspend Click2Gov use during the probe. A forensics auditor engaged by WAPA initially concluded on October 18 that the payment portal had not been breached, though this assessment faced external skepticism given the timing and pattern of prior Click2Gov incidents.

On October 22, a second customer reported fraudulent activity on their payment card linked to WAPA transactions, prompting renewed contact with CST. CST subsequently confirmed a cyberattack against the Click2Gov application, characterizing it as a novel, previously unseen exploit. The breach resulted in unauthorized access to customer payment card data, with an undetermined number of individuals experiencing credit or debit card fraud. Central Square deployed a security patch to address the vulnerability on October 25, 2019. This incident occurred amid a series of Click2Gov-related breaches between 2017 and 2019 affecting multiple municipalities, though CST did not publicly clarify whether the WAPA attack shared technical commonality with prior compromises. The breach disrupted WAPA’s payment systems and necessitated customer fraud monitoring, while raising broader questions about the software’s security posture.

Sources

Sources available to members: 1 source.

CSIDB