Updated at 3 p.m. to reflect a correction that while 62 email accounts were affected in the phishing attack, only one account appeared to have been compromised.
One city employee’s email account was compromised in a phishing attack this week, but officials said the city government doesn’t appear to have lost anything in the incident.
In a phishing attack, scammers send emails that appear to come from a known source, but redirect the recipient to a malicious website. That website, in turn, captures personal information, such as employee logins, to advance the scam. In the city’s case, an email spoofed a known engineering firm to lure 62 employees to a website for more information.
Melissa Kraft, the city’s information technology director, said her department learned of the possible compromise about 3 p.m. Wednesday. By 7 p.m., all 62 affected accounts had been reset. Technology employees looked but could find no impact on the city’s systems, including the billing department, she added.
“We got the bad emails out of the system and we reset the accounts,” Kraft said.
Nor was any personal information compromised, Kraft said.
Last year, a phishing attack in San Marcos compromised the W-2s for all 800 city employees after a scammer captured login credentials. Other cities have lost money when scammers are able to get into the billing system, Kraft said.
Denton’s IT department got in touch with Microsoft, the city’s email provider, as well as the engineering firm to let them know its system was compromised and the company was being impersonated. The department also reported the incident to Denton police, although without any known losses, there isn’t much of a case to pursue, Kraft said.
But that doesn’t mean the department has no leads on who tried to get into City Hall without being detected. The city’s technology department also set up a “sandbox,” or a laptop that isn’t linked to the city’s systems, to run an email through the malicious website to see what would happen.
“We traced it to someone in Florida,” Kraft said.
Avoiding phishing scams
Scammers can lure you by using official-looking logos and spoofing the address of a legitimate company. The Federal Trade Commission offers these tips to avoid phishing scams:
Use care when opening attachments or clicking on links in emails, even from people you know. If their account and computer is compromised, yours could be next. Those attached files and links can contain code that weakens your computer’s security.
Type the website address or phone number yourself. The displayed link or phone number company may be hiding the true destination. Don’t click; look it up and type it in yourself.
Call and check. Don’t follow the trail set for you by the scammer. Call the number you know from the phone book or your address book.
Turn on two-factor authentication. This type of security is becoming more widely available. Two-factor authentication requires both your password and an second piece of information for account logins. Depending on the security, the additional option could be a code sent to your phone, or a random number generated for you. So, even if your password is compromised, the scammer cannot get in without that second piece of information. And you are alerted indirectly whenever someone is trying to access your account.
Keep your security up to date and back up your files. Regular saves to an external hard drive or cloud storage helps protect your files from viruses or from being hijacked in a ransomware attack.
Report phishing emails and texts. Forward those phishing emails to spam@uce.gov and to the organization impersonated in the email. While the email headers often are hidden, be sure to include the full email header. Search the name of your email service with “full email header” for tips on how to retrieve that information.
You also can report to reportphishing@apwg.org. The Anti-Phishing Working Group is made up of computer companies, financial institutions and law enforcement agencies.
PEGGY HEINKEL-WOLFE can be reached at 940-566-6881.
