City of Hailey
Incident posture
Linked entities
- Victim
- City of Hailey
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A municipal government discovered suspicious activity on an employee email account and immediately launched an investigation with legal counsel and a third-party digital forensics firm. The investigation subsequently confirmed that the account had been breached, though the full scope of the incident remained under review at the time of the regulatory notification. The types of personal information exposed included names, Social Security numbers, and driver's license numbers belonging to local residents. Notifications were issued to the state Attorney General, the state Chief Information Security Officer, and the Office of Risk Management as the forensic review of the compromised mailbox continued.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On January 30, 2025, the City of Hailey discovered suspicious activity on an employee email account. The City immediately initiated an investigation, engaging both legal counsel and a nationally recognized cybersecurity and digital forensics firm to determine the scope and nature of the incident. This initial discovery prompted the City to take prompt action to assess whether any data had been compromised and to begin gathering information about the affected systems. As part of its response, the City also began coordinating with relevant state authorities, including notifying the Office of the Idaho Attorney General of the situation.
Following the initial discovery, the investigation continued over the subsequent weeks. On Friday, February 14, 2025, the City determined that the employee email account had been subject to a breach of the security of the system, as defined in Idaho Code ยง 28-51-104(2). This determination was made after a thorough review conducted in collaboration with the digital forensics firm and legal counsel. Upon confirming the breach, the City began working to identify the specific contents of the impacted email account and to determine which individuals' information may have been affected. At that stage of the investigation, the affected data was identified as including Idaho residents' names, Social Security numbers, and driver's license numbers.
The City of Hailey, through its legal representation at Eckert Seamans Cherin & Mellott, LLC, formally notified the Office of the Idaho Attorney General's Consumer Protection Division of the incident via a notice letter dated February 14, 2025. The notice was sent by Matthew H. Meade, Esq., on behalf of the City, and outlined the chronology of events, the nature of the data potentially affected, and the City's ongoing response efforts. In addition to notifying the Attorney General, the City also communicated the incident to the Information Technology Services Chief Information Security Officer and the Office of Risk Management. The City indicated its intention to continue providing significant updates as the investigation progressed, signaling an ongoing commitment to transparency and remediation as additional details about the scope of the breach became available.
Sources
Sources available to members: 1 source.