HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedTargetedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
City of Lewes
bd_d74b328c024d1f05 · schema v1 · pii pii-v1
Full breach record for City of Lewes →Board of Public Works City of Lewes notified customers on May 29, 2019, of a data breach discovered on May 28, 2019. A hacker exploited a software vulnerability in the utility's customer information system provider to copy customer data, including names, email addresses, credit/debit card numbers, and financial account credentials. The utility isolated the affected system, notified the vendor, and engaged with state and federal agencies. No actual misuse of information was known at the time of notification.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2020/06/LewesBPW.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 29, 2019
- Raw hash
- 7ec0f866099c2779d26ce925ca13ee26b3d406e4c12409b106f65af189cf5531
Reporting entity
- Name
- Board of Public Works City of Lewesnorm: board of public works city of lewes
Victim entity
- Name
- City of Lewesnorm: city of lewes
- Domain
- lewes.civicweb.net
Incident
- Discovered
- May 28, 2019
- Materiality determined
- —
- Notification sent
- May 29, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- notified by federal and state agenciesin contact with state and federal agencies regarding the incident
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- ≤1 day(1 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.