DisclosureLens
Social EngineeringGovernmentGovernmentBECStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDMediumContained

City of Roanoke

bd_25bffebae40ee155 · schema v1 · pii pii-v2

Severity

Medium

Discovered

May 11, 2026

Filed

Aug 17, 2026

To disclose

14 weeks

Affected

2

Confidence

65%
Full breach record for City of Roanoke4 incidents on file

The City of Roanoke experienced a business email compromise (BEC) resulting in unauthorized access to departmental data on May 6, 2026. The City became aware of the incident on May 11, 2026. Two potentially affected individuals were identified, with exposure of first initial, last name, and Social Security numbers. The actor's access was terminated, and third-party cybersecurity experts were engaged. The City notified the FBI and the New Hampshire Attorney General.

Incident timeline

undetected · 5 days
discovery → filing · 14 weeks / 98 days

May 6, 2026

Begins

May 11, 2026

Discovered

Aug 17, 2026

Filed

vs. sector median

+3 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.