Menu
Browse

Cyber Incident Victim: City of Noblesville

Date:

Oct 2024

Location:

United States of America

Summary

The City of Noblesville experienced an external system breach involving unauthorized access to personal information, including names combined with other identifiers. The incident impacted 1,841 individuals, with one Maine resident affected. Following discovery months after the breach, written notifications were issued, and impacted individuals were offered 12 months of credit monitoring services through IDX. The breach was attributed to hacking, though specific technical details or attacker motives were not disclosed in the notification.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The City of Noblesville, Indiana, experienced a cybersecurity incident involving an external system breach through hacking on October 22, 2024. The breach remained undetected until January 22, 2025, when the city discovered unauthorized access to its systems. The compromised data included names combined with other personal identifiers, though the specific types of additional information were not detailed in public notifications. A total of 1,841 individuals were affected by the breach, including one resident of Maine. The delayed discovery indicated a three-month period during which attacker activity persisted without detection. No evidence suggested prior breaches within the preceding twelve months. The city engaged legal counsel from McDonald Hopkins PLC to manage breach response protocols.

Cyber Incident Image

Noblesville initiated written notifications to affected individuals on February 18, 2025, outlining the nature of the incident and the categories of exposed information. The city offered twelve months of complimentary credit monitoring and identity theft protection services through IDX to mitigate potential harm to impacted persons. Documentation submitted to Maine’s Attorney General included a redacted copy of the notification letter, confirming adherence to state disclosure requirements. No additional technical details regarding attack vectors, containment measures, or system vulnerabilities were disclosed publicly. The breach’s operational consequences for municipal services or internal systems remained unspecified in regulatory filings. Legal representatives confirmed completion of consumer notifications within the mandated timeframe following the discovery date.

Sources
Sources available to members
1 source