CSIDB logo
Incident

City of Saint John

Incident posture

Attack window
Dec 2018
Location
Canada
Status
Historical
CIA posture
Available to members
Updated
2026-01-10 01:42

Linked entities

Victim
City of Saint John
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A municipal parking payment system breach potentially exposed customer names, addresses, and credit card information due to a vulnerability in third-party Click2Gov software provided by CentralSquare Technologies. The city disabled its online payment portal after discovering the incident through external media reports, as the service provider failed to directly notify them of the widespread issue impacting multiple North American municipalities. Officials expressed concern over the provider's negligence in communication while emphasizing their commitment to data protection and advising vigilance regarding financial account activity.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On December 22, 2018, the City of Saint John discovered a data breach in its online parking ticket payment system, prompting immediate shutdown of the platform. The breach potentially exposed customer names, addresses, and credit card information processed through the Click2Gov software provided by third-party vendor CentralSquare Technologies. Mayor Don Darling confirmed the city issued a public notice the same afternoon the breach was identified, emphasizing the non-negotiable importance of citizen privacy and payment security. The breach originated from an unknown external party exploiting vulnerabilities in CentralSquare's Click2Gov application, which served multiple municipalities across North America. City officials expressed frustration that CentralSquare Technologies failed to directly notify them about the security compromise, with Saint John learning of the incident through media reports documenting similar breaches in other jurisdictions using the same software.

Mayor Darling characterized CentralSquare's failure to disclose the breach as potentially violating their service agreement, describing the omission as "serious and neglectful." The city directed affected customers to monitor their financial accounts for unauthorized transactions and contact their banking institutions if suspicious activity occurred, while advising potential identity theft victims to report to police. No specific timeframe for the breach's duration or exact number of impacted Saint John residents was disclosed in the public statement. The incident prompted internal reviews of data protection protocols and third-party vendor notification obligations, though the city confirmed no additional systems beyond the parking ticket portal were compromised. Saint John formally apologized for the inconvenience while maintaining its commitment to data security, though restoration timelines for the payment platform remained unclear at the time of reporting.

Sources

Sources available to members: 1 source.

CSIDB