City of Aurora
Incident posture
Linked entities
- Victim
- City of Aurora
- Threat actors
- 0 actors
- Sources
- 3 sources
Timeline
Summary
The city of Aurora experienced a social engineering fraud in which an employee was tricked by a phone caller posing as a bank representative into revealing sensitive account information, leading to unauthorized ACH transfers of nearly $1.1 million from municipal payroll accounts. Officials said there is no evidence that the city's network or data systems were compromised, and no resident data was affected. The incident was discovered the day after it occurred, prompting notification of law enforcement, the financial institution, and the engagement of outside cybersecurity experts; the FBI acknowledged awareness but did not confirm an investigation. Some of the lost funds have been recovered, and the city continues to work with partners to recover the remainder while maintaining insurance coverage and reviewing internal procedures, training, and vendor contracts to strengthen defenses.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On April 29 a city employee received a phone call from someone impersonating a bank representative; the caller used deceptive tactics to appear legitimate, establish trust and create a false sense of urgency, which prompted the employee to disclose sensitive account information. That information was used to initiate fraudulent ACH transfers from the city’s payroll bank accounts, resulting in a loss of nearly $1.1 million. The city discovered the fraudulent activity on April 30, the day after it occurred, when officials noticed the unauthorized transactions. Upon discovery Aurora notified law enforcement, contacted its financial institution, activated its incident response procedures and engaged outside cybersecurity experts to assist with the investigation. Mayor John Laesch described the incident as a very sophisticated cyber attack but emphasized that there is currently no evidence the city’s network or data systems were compromised, nor any indication that resident data was affected.
The Aurora Police Department confirmed that a reported incident involving the city is under investigation, and the FBI has acknowledged awareness of the matter while declining to comment on whether it is conducting an investigation due to U.S. Department of Justice policy. City officials have stated that they are working closely with law enforcement and financial institutions to recover a portion of the funds, and they have noted that the city maintains insurance coverage for losses of this type. Aurora has already recovered some of the lost funds and intends to continue working with law enforcement until all of it—or more—is recovered, although the exact amount recovered has not been disclosed. The city is awaiting the results of its financial institution’s forensic audit to determine whether any employee data stored on its systems may have been impacted, and it has said that employees will be notified if any of their information is found to have been affected. Aurora has also contracted with NuHarbor Security, Inc. for cyber‑security‑related services, a relationship that began toward the end of the previous year, and the City Council approved the KnowBe4 cybersecurity training course for employees around the same time; the city regularly conducts internal training and phishing exercises for staff.
Officials have said that they will continue to refine internal procedures, security measures and employee training programs to strengthen protections and help prevent similar incidents in the future. They have stressed that the city takes its responsibility to protect public resources seriously and appreciates the cooperation of staff, financial institutions and law enforcement agencies as the matter is addressed. No further specifics about the attacker’s identity or methods have been released, and the investigation remains active and ongoing.
Sources
Sources available to members: 3 sources.