Cyber Incident Victim: City of Aurora
Timeline
Summary
Aurora discovered fraudulent ACH payments after detecting unauthorized activity the day after it occurred and determined that its internal systems were not compromised. Authorities have not released a specific loss amount while an active investigation involving police and cybersecurity partners continues to determine the total loss. Some of the missing funds have already been recovered and the city expects to recover additional amounts through insurance and ongoing law‑enforcement efforts. The city has contracted NuHarbor Security for cyber‑security services and uses KnowBe4 for regular employee training and phishing exercises with internal training conducted regularly. Officials have declined to discuss potential disciplinary actions or investigative details while the case remains active.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On April 30, 2024 the city of Aurora discovered fraudulent activity that had occurred the previous day, April 29, when unauthorized ACH transactions were detected in city accounts. Mayor John Laesch described the incident as a “very sophisticated cyber attack” but stated that the city believes its internal systems were not compromised. The Aurora Police Department, together with other partners, began an active investigation to determine the exact amount of money that was transferred, and officials said they did not want to compromise the integrity of the investigation by releasing specifics. Mayor Laesch declined to disclose a dollar amount or even a ballpark estimate of the funds that went missing, and the police department confirmed only that a reported incident involving the city was under investigation, noting that further details were unavailable because of the ongoing nature of the case.

The fraudulent payments were identified as ACH transactions, which are electronic transfers of money between banks and credit unions that typically require a bank account number and routing number for bill payments. After becoming aware of the fraud, the city took immediate steps to mitigate the impact and begin recovery efforts, as noted in an official statement. Officials expressed hope that some of the lost funds could be recovered and emphasized that the city maintains insurance coverage for incidents of this type. Aurora has already recovered some of the lost money and said it will continue working with law‑enforcement authorities until all of the missing funds—or more—are returned, although Mayor Laesch did not specify the amount already recovered.
In response to the incident, city officials stated they are not commenting on specific departmental details, investigative findings, personnel matters, or any other aspects of the ongoing investigative process to avoid jeopardizing the case. The Aurora Police Department reiterated that more information is not available at this time because the investigation remains active and ongoing. The city has also confirmed that it holds regular internal training and phishing exercises for staff, which are required as part of its cybersecurity hygiene. Additionally, Aurora contracted with NuHarbor Security, Inc. for cyber‑security‑related services toward the end of the previous year, and the City Council approved the KnowBe4 cybersecurity training course for employees around the same time.
City leaders have said they have not made the incident public because the investigation is still underway, and they continue to cooperate with internal and external partners as the case proceeds. Officials remain hopeful that further funds will be recovered through the ongoing law‑enforcement effort and that the city’s insurance coverage will assist in addressing any losses. The investigation remains active, and no additional details have been released at this time.
