CSIDB logo
Incident

City of Keokuk

Incident posture

Attack window
Jan 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-30 00:00

Linked entities

Victim
City of Keokuk
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A data breach impacting the City of Keokuk resulted from a criminal phishing email that enabled unauthorized access to 2017 W-2 tax forms containing personal information of current and former employees and elected officials. The compromised data did not include credit card details, bank account information, or affect employees hired during the current calendar year. Law enforcement agencies, including federal authorities, were engaged to investigate the incident, though no suspect was identified at the time of reporting. Impacted individuals received notifications via postal mail and were offered complimentary credit monitoring and identity theft protection services. The municipality emphasized its commitment to information security while confirming the breach's limited scope to tax forms.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 30, 2018, the City of Keokuk discovered a data breach involving unauthorized access to sensitive employee information through a criminal phishing email. The breach occurred earlier that day when an attacker successfully obtained an electronic file containing 2017 Form W-2 tax documents for current and former city employees and elected officials. The phishing attack specifically targeted city systems but did not compromise credit card details, bank account information, or affect employees hired during the 2018 calendar year. Upon detection, city administrators immediately initiated an internal investigation and reported the incident to law enforcement authorities. The stolen W-2 forms contained personally identifiable information typically included in tax documents, though the exact number of affected individuals was not disclosed in public statements.

The City of Keokuk coordinated with the Keokuk Police Department and federal law enforcement agencies to investigate the breach, though no suspect had been identified as of February 4, 2018. Impacted individuals received notification through U.S. Mail and were offered complimentary credit monitoring and identity theft protection services. City Administrator Aaron Burnett confirmed the municipality prioritized containment and victim support while maintaining regular operations. The city's public statement emphasized their commitment to information security and pledged continued measures to protect sensitive data, though no specific technical details about the phishing mechanism or system vulnerabilities were disclosed. Forensic analysis confirmed the breach scope remained limited to the 2017 W-2 forms with no evidence of subsequent unauthorized access or expanded data compromise beyond the initial theft.

Sources

Sources available to members: 1 source.

CSIDB