CSIDB logo
Incident

City of Waco

Incident posture

Attack window
Nov 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-13 00:00

Linked entities

Victim
City of Waco
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A city experienced a cybersecurity breach affecting its online water bill payment system via the Click2Gov portal, compromising customer payment data. Attackers exploited a vulnerability in the third-party software, impacting over 8,000 customers who used the portal during the incident period, while in-person credit card transactions remained unaffected. The municipality notified affected individuals via mailed letters advising vigilance against fraud and established a dedicated support hotline. The software vendor confirmed resolving the vulnerability after limited breaches were reported across its customer base. This incident followed a pattern of repeated attacks targeting the same payment platform in multiple jurisdictions.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On November 8, 2019, the City of Waco was notified of a security breach affecting its online water bill payment system operated through the Click2Gov portal developed by CentralSquare Technologies. The breach exposed payment information of customers who used the web portal between unspecified dates preceding this notification. City officials confirmed that approximately 8,000 customers—representing nearly two-thirds of the typical monthly online payment volume of 12,500 transactions—had their data compromised during the incident period. The breach exclusively impacted online payments processed through Click2Gov, with in-person credit card transactions at water office locations remaining unaffected. CentralSquare Technologies acknowledged a vulnerability in the Click2Gov software that facilitated unauthorized access but stated it had been patched, while emphasizing only a "limited number" of clients reported breaches.

The City of Waco initiated customer notification procedures by mailing letters to all identified affected individuals within weeks of discovering the breach. These communications advised recipients to monitor financial statements for fraudulent activity and provided specific protective guidance. Municipal spokesman Larry Holze confirmed the dispatch of notifications and established a dedicated telephone hotline (833-947-1419) operational on weekdays to address resident inquiries. With 44,000 total water customers in the municipality, the incident impacted approximately 18% of the customer base through the compromised online payment channel. No details regarding the specific types of data exfiltrated or forensic findings about the attack methodology were disclosed by city officials or CentralSquare Technologies in the available reporting.

Sources

Sources available to members: 1 source.

CSIDB