Cyber Incident Victim: City of San Luis
Date:
Feb 2023
Location:
United States of America
Summary
The City of San Luis experienced unauthorized access to an employee's email account, compromising personal and health information of 6,848 individuals. Exposed data included names, addresses, driver's license numbers, health insurance details, medical information, dates of birth, and Social Security numbers. The breach occurred over several weeks before detection, with forensic review confirming the scope before notifications were sent to affected parties after contact verification.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
The City of San Luis, Arizona, experienced a data breach involving unauthorized access to an employee’s email account containing protected health information. Suspicious activity within the email account was first detected on March 7, 2023, prompting an immediate forensic investigation. The investigation confirmed that unauthorized individuals had accessed the account over a 23-day period, from February 1 to February 23, 2023. During this timeframe, attackers gained persistent access to emails and attachments stored within the compromised account. The forensic review of all accessible content within the account, including attachments and message bodies, concluded on May 4, 2023. This review process was necessary to identify the specific individuals impacted and the types of exposed data. Following the investigation, the City undertook a verification process to confirm mailing addresses for affected individuals before issuing breach notifications.

The breach exposed sensitive information belonging to 6,848 individuals. Compromised data included full names, residential addresses, driver’s license numbers, health insurance details, medical information, dates of birth, and Social Security numbers. The City did not specify whether the attackers exfiltrated data or merely accessed it, nor did they identify the threat actors involved. Response actions focused on notifying all affected individuals through mailed letters after completing address verification. While the City did not publicly disclose whether credit monitoring services were offered, standard breach remediation practices suggest such measures were likely implemented given the exposure of Social Security numbers and medical data. No evidence of data misuse was reported at the time of disclosure, and the City did not detail specific technical security improvements enacted following the incident beyond concluding their forensic review and notification processes.
