Menu
Browse

Cyber Incident Victim: City of Waco

Date:

Nov 2019

Location:

United States of America

Summary

A city experienced a cybersecurity breach affecting its online water bill payment system via the Click2Gov portal, compromising customer payment data. Attackers exploited a vulnerability in the third-party software, impacting over 8,000 customers who used the portal during the incident period, while in-person credit card transactions remained unaffected. The municipality notified affected individuals via mailed letters advising vigilance against fraud and established a dedicated support hotline. The software vendor confirmed resolving the vulnerability after limited breaches were reported across its customer base. This incident followed a pattern of repeated attacks targeting the same payment platform in multiple jurisdictions.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On November 8, 2019, the City of Waco was notified of a security breach affecting its online water bill payment system operated through the Click2Gov portal developed by CentralSquare Technologies. The breach exposed payment information of customers who used the web portal between unspecified dates preceding this notification. City officials confirmed that approximately 8,000 customers—representing nearly two-thirds of the typical monthly online payment volume of 12,500 transactions—had their data compromised during the incident period. The breach exclusively impacted online payments processed through Click2Gov, with in-person credit card transactions at water office locations remaining unaffected. CentralSquare Technologies acknowledged a vulnerability in the Click2Gov software that facilitated unauthorized access but stated it had been patched, while emphasizing only a "limited number" of clients reported breaches.

Cyber Incident Image

The City of Waco initiated customer notification procedures by mailing letters to all identified affected individuals within weeks of discovering the breach. These communications advised recipients to monitor financial statements for fraudulent activity and provided specific protective guidance. Municipal spokesman Larry Holze confirmed the dispatch of notifications and established a dedicated telephone hotline (833-947-1419) operational on weekdays to address resident inquiries. With 44,000 total water customers in the municipality, the incident impacted approximately 18% of the customer base through the compromised online payment channel. No details regarding the specific types of data exfiltrated or forensic findings about the attack methodology were disclosed by city officials or CentralSquare Technologies in the available reporting.

Sources
Sources available to members
1 source