CSIDB logo
Incident

Cucamonga Valley Water District

Incident posture

Attack window
Aug 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-07 00:00

Linked entities

Victim
Cucamonga Valley Water District
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Cucamonga Valley Water District experienced a data breach involving its third-party payment portal, Click2Gov, operated by vendor Central Square. Unauthorized access occurred over several weeks on a server processing one-time customer credit card payments, though investigators found no conclusive evidence that personal information was actually exfiltrated. Central Square addressed the vulnerability to prevent further access and offered affected customers complimentary credit monitoring services. The water district is reassessing its vendor relationship and security protocols while confirming the incident did not impact all customers. CVWD emphasized its commitment to protecting customer data and proactively notified potentially affected individuals.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Cucamonga Valley Water District (CVWD) experienced a data security incident involving its Click2Gov web payment portal, operated by third-party vendor Central Square. Between August 26, 2019, and October 14, 2019, unauthorized actors breached a server used to process one-time credit card payments from customers. CVWD was notified of the breach by Central Square, which maintained and operated the compromised infrastructure. The breach specifically impacted the external payment system rather than CVWD's internal networks. Central Square initiated an investigation with assistance from a cybersecurity firm, though investigators found no conclusive evidence confirming exfiltration of customer payment data. The scope was limited to customers who made one-time payments through Click2Gov during the seven-week exposure window, excluding all other CVWD account holders.

Central Square implemented security measures to prevent further unauthorized access to the payment portal following the investigation. As a precautionary measure, the vendor offered affected customers a twelve-month subscription to TransUnion's credit monitoring service. CVWD began notifying potentially impacted individuals via direct mail with breach details and remediation options. The water district publicly acknowledged the incident on December 4, 2019, emphasizing its commitment to customer privacy while confirming reevaluation of its vendor relationship and Central Square's security protocols. No operational disruptions to water services occurred, and CVWD maintained regular customer service channels throughout the incident response. The organization established dedicated phone support through Epiq Global and its internal customer service team to address public inquiries regarding the breach.

Sources

Sources available to members: 1 source.

CSIDB