City of Idaho Falls
bd_1f944cef51c0042d · schema v1 · pii pii-v2
Full breach record for City of Idaho Falls →On September 14, 2026, an external party accessed a City of Idaho Falls employee's Microsoft 365 mailbox using a stolen or replayed authentication token. The unauthorized session lasted approximately 60-75 seconds and involved automated access to roughly 70 email items, including targeted access to archived payroll direct-deposit documentation. The City became aware of the confirmed breach on September 17, 2026, following a technical investigation prompted by a second alert. One Idaho resident employee was affected. The City disabled the account, reset credentials, revoked sessions, and enforced MFA re-registration. The investigation is complete.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 14, 2026
Begins
Sep 17, 2026
Discovered
Sep 18, 2026
Filed
vs. sector median
11 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.