Town of Middleburg Responds to Cybersecurity Incident
What Happened? On or about January 30, 2023, the Town of Middleburg (the “Town”) became aware that it was the victim of a data incident. Immediately, the Town’s management and Information Technology contractor (including cybersecurity experts) were engaged to investigate the incident, secure personal information, and protect the Town’s network from compromise.
To date, our investigation revealed that sometime between January 25 and January 31, 2023, malicious actors gained access to a single Town employee’s Outlook email account, exfiltrated vendor information, and impersonated the vendor to request payment from the Town. There is no definitive evidence that anyone’s personal information was accessed. However, because an unknown actor gained access to the employee’s email account, we are providing this notice out of an abundance of caution. To date, we have not received any indication that anyone’s information has been misused by an unauthorized individual.
What Information Was Involved? It is possible that the Personal Identifying Information of 102 persons was seen or accessed. Out of an abundance of caution, the Town is informing those 102 persons directly by mail to inform them of this incident, to provide them information on resources to protect their interests, and to give them phone numbers to contact if they need more information.
What We Are Doing. We take the confidentiality, privacy, and security of information in our care seriously. Information technology experts were immediately engaged and commenced an investigation to determine the nature and scope of the incident. While investigation remains ongoing, we are taking steps now to implement additional safeguards and review policies and procedures relating to data privacy and security.
It is important to note that no servers, systems, or other data was accessed, and this incident was limited to one mailbox.
The Town has implemented additional security measures designed to prevent a reoccurrence of such incidents and to protect the privacy of our employees, residents, and vendors. Among other steps taken, we have installed a more robust cybersecurity solution across our network, strengthened our system’s architecture, and implemented stronger policies to prevent future attacks.
We apologize for any inconvenience that may have arisen as a result of this incident and reaffirm our commitment to ensuring the safety of the data held in the Town’s possession.