Post personnel files on 'dark web' after ransom demand
Hackers posted data this week on the "dark web" from City of Beacon computers, including the personnel files of hundreds of current and past employees.
A group known as RansomHouse announced on Aug. 6 that it had gained access to the network at least two weeks earlier. It posted thousands of documents online this week after saying its ransom demands were ignored. As of Tuesday (Aug. 18), a counter indicated 7,260 people had viewed the files, which include folders titled Assessor, Building, Clerk, Finance and HR.
"We are aware of reports regarding a cyber event and are actively investigating," City Administrator Ben Swanson said in a statement on Tuesday. "We have engaged our internal security team and third-party cybersecurity specialists to support the investigation and ensure our environment remains secure. As the review is ongoing, we are unable to provide more at this time."
The Current reviewed the hack and found that, while the files contain information already public, such as budget documents, they also include personal and financial information for hundreds of current, former and retired city employees, including police officers and firefighters, that could be used for fraud.
In addition, the documents appear to contain the contents of computers used by the city administrator, building inspector, finance director, tax assessor and human resources director, among other employees.
Under a state law enacted last year, municipalities must report breaches and payment demands within 72 hours to the state Division of Homeland Security and Emergency Services, the Division of Consumer Protection, the attorney general and the state police. They must also notify anyone whose data was stolen within 30 days.
According to sites that track hackers, RansomHouse has targeted more than 200 companies and municipalities worldwide since 2021. Along with Beacon, its recent victims include the City of McMinnville, Oregon; Prince George's County, Maryland; and the Warren County Sheriff's Office in Kentucky.
Once they have breached a network through methods such as "phishing" for credentials through email links or installing rogue software (malware), hackers demand payment. Some encrypt data so it can't be accessed; others, like RansomHouse, download sensitive material and threaten to post it online.
Install security software, such as that offered by avg.com, to your computer. Its free version has basic functions and can be upgraded for a fee. Also enable "two-factor authentication" whenever it's offered (i.e., you will need to request a code by text or email to log in to an account).
Be cautious about any email that asks you to click on a link to update or verify information. By hovering your mouse over the link, you can see the address it will send you to. Better yet, go directly to the source. For instance, if an email appears to be from your bank, go to the bank's website to log in or call.
Be especially cautious about emails that claim to have invoices or important documents attached. Antivirus software will usually flag these messages as suspicious or prevent malware from being installed, but a better strategy is to go directly to the source if you have doubts.
Back up your computer regularly so that it can easily be restored if damaged or seized by hackers. You can also encrypt your hard drive using programs such as BitLocker or FileVault to protect it from unauthorized access.
In online posts, RansomHouse claims it provides a service, identifying security flaws, for which it deserves compensation. Like a burglar blaming a homeowner for leaving a window unlocked, it argues the villains are companies and municipalities that don't protect their data. In a message directed at City of Beacon officials, it wrote: "Dear management of City of Beacon, we were waiting for you for quite some time, but it seems that your IT department decided to conceal the incident that took place in your...