CSIDB logo
Incident

Roanoke City

Incident posture

Attack window
May 2026
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-09-12 22:20

Linked entities

Victim
Roanoke City
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2026
Discovered
May 2026
Disclosed
Aug 2026
Resolved
May 2026

Summary

Roanoke experienced a phishing email that compromised an employee's city email account, granting an attacker access to limited departmental data including names, Social Security numbers, passport numbers, and financial account information. The account was secured within a day, but a forensic review delayed resident notification for several months, during which the city reported no confirmed misuse of the exposed information.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 6, 2026, a city employee in Roanoke, Virginia opened a phishing email that appeared legitimate. The interaction compromised the employee’s city email account and gave an outside party a foothold into at least part of the municipal network. The city locked the compromised account within 24 hours, cutting off access by May 7, 2026. Around May 11, 2026, Roanoke contacted its cyber insurance carrier to launch a formal investigation, which was supported by outside information technology experts.

The investigation found that the phishing software harvested the employee’s email contacts to gather additional login credentials, a lateral‑movement tactic after gaining a working mailbox. Although the malicious actor’s access was terminated soon after detection, the actor had been able to access a limited set of departmental data before being stopped. The exposed data included first and last names, Social Security numbers, passport numbers, and financial account information. Notification letters were not sent until August 24, 2026, roughly three and a half months after the account was locked, due to the time required for the insurer‑led forensic review of whose data was affected.

The city’s notification stated that, to date, it had received no indication that the exposed personal data had been misused. Roanoke engaged federal law enforcement, and multiple outlets reported the incident was referred to the FBI as part of its response. The direct costs of the investigation, credit monitoring offers, and any additional security tooling were partially covered by the city’s cyber insurance, while the reputational and potential legal costs stemmed from the lengthy notification delay. Virginia’s breach notification law (Va. Code § 18.2‑186.6) requires notification without unreasonable delay after discovering a breach involving Social Security numbers, driver’s license numbers, or financial account information with security codes, and the three‑and‑a‑half‑month gap has been noted as potentially inconsistent with that standard.

Sources

Sources available to members: 1 source.

CSIDB