Cyber Incident Victim: Hollywood Park, TX
Date:
Mar 2019
Location:
United States of America
Summary
A municipality in Texas fell victim to a cyber theft attempt involving nearly half a million dollars, attributed to suspected international criminals. Following the incident, collaborative efforts with the U.S. Secret Service enabled the recovery of approximately $300,000, while roughly $200,000 remained unrecovered and became the subject of dispute after being traced to a Turkish financial institution. Despite investigations spanning over a year, no arrests were made in connection with the attack, leaving accountability unresolved for the outstanding funds.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 5, 2019, Hollywood Park, a small suburb of San Antonio, Texas, experienced a cyber theft incident involving an attempted theft of nearly $500,000. The perpetrators, described as likely international cyber-criminals, successfully diverted municipal funds through unauthorized electronic transfers. The town discovered the theft shortly after the fraudulent transactions occurred and immediately engaged the United States Secret Service to investigate the incident and trace the stolen funds. Through collaborative efforts with federal authorities, Hollywood Park managed to recover approximately $300,000 of the stolen amount. A significant portion of the remaining funds—totaling nearly $200,000—was traced to a bank account in Turkey, where recovery efforts became complicated by jurisdictional and legal challenges. No arrests had been made in connection with the crime as of 17 months following the incident, despite ongoing investigative efforts.

The financial impact of the unrecovered $200,000 created operational challenges for Hollywood Park and sparked disputes regarding liability for the loss. Municipal representatives indicated unresolved disagreements over which parties should bear responsibility for the funds that remained in foreign banking institutions. The incident highlighted vulnerabilities in the town's financial transaction processes but did not result in public disclosures about specific technical attack vectors or internal security failures. Recovery efforts remained focused on legal and diplomatic channels to reclaim the outstanding funds from Turkey, with no additional public updates provided about enhanced cybersecurity measures or system changes implemented post-incident. The case demonstrated the complexities of international fund recovery following cyber-enabled financial crimes against municipal entities.
