City of Medford billing records hacked

Mail Tribune (Medford, OR — Wayback)

2018-07-24

Document text

More than 1,800 customers who pay for city of Medford utility, permit and business license bills by credit or debit cards may have had financial information compromised. The city said Monday the security breach came in two waves — Feb. 18 to March 14 and March 29 to April 16. An unnamed financial institution notified the city its online payment system was possibly compromised on April 19. “They expressed concern for some kind of compromise, but didn’t know what was in our system,” Deputy City Attorney Eric Mitten said. “That’s when we launched our investigation.” Forensic investigators from Kroll, a Manhattan-based technology-enabled intelligence and information management firm, determined on June 5 that malware was used to gather payment card information, including credit or debit card numbers, cardholder names, as well as expiration dates and CVV codes, from the Superion Click2Gov system used by Medford. A letter from Mitten dated July 23 has been sent to 1,842 potentially affected cardholders. “We regret that this incident occurred and we are working diligently to resolve this incident,” Mitten wrote. “Upon learning of this incident, we immediately commenced a forensic investigation and took steps to address and contain this incident.” Social Security numbers were not affected, he wrote cardholders. “Based upon an independent forensic investigation, it appears that an unauthorized individual was able to gain access to portions of our website and install software that was designed to capture payment card information as it was inputted on the website,” Mitten wrote. Although the website was temporarily disabled until it was re-secured, the city didn’t go public about the breach or investigation for another seven weeks. Mitten said Monday the city didn’t want to alarm people who weren’t affected by the breach. “We’ve been working closely with the forensic investigators to get more specific information and to pinpoint who may have been affected,” Mitten said. “If we would have announced it immediately, we wouldn’t have known who was and who wasn’t affected; we recommend everyone monitor their credit cards, regardless.” Mitten didn’t know why there was a gap between attacks, or why it wasn’t detected earlier. “It’s beyond my area of expertise,” he said. “Kroll’s investigation isn’t finalized.” The malware was a zero-day-style attack, he said. A zero-day attack exploits a previously unknown security vulnerability, sometimes taking advantage of a security vulnerability the same day it becomes generally known. The letter notes three other municipalities — Beaumont, Texas; Oceanside, California; and Goodyear, Arizona — had similar malware issues. Newspapers and television stations have reported Superion Click2Gov hacks taking place last summer in Bozeman, Montana, and in multiple Florida municipalities during 2017. In June, Risk Based Security Executive Vice President Inga Goddjin blogged about the company’s investigations into similar breaches in Oxnard, California, on May 25 and in Wellington, Florida, on June 6. Superion, which is based in Lake Mary, Florida, reportedly issued a patch for the vulnerability that continues to lead to the growing string of breaches. Mitten suggested in his letter that potentially affected customers review credit and debit card account statements as soon as possible to determine whether there are any discrepancies or unusual activity listed. “We urge you to remain vigilant and continue to monitor statements for unusual activity going forward,” he wrote. “If you see anything you do not recognize, you should immediately notify the issuer of the credit or debit card as well as the proper law enforcement authorities.” The city has set up a dedicated call line to field questions at 1-844-808-4890, between 6 a.m. and 6 p.m. Monday through Friday. Reach reporter Greg Stiles at 541-776-4463 or [email protected]. Follow him on Twitter at www.twitter.com/GregMTBusiness or www.facebook.com/greg.stiles.31.