Arlington Responds to Cybercrime

Arlington Responds to Cybercrime
<span class="bsf-rt-reading-time"><span class="bsf-rt-display-label" prefix="Reading Time"></span> <span class="bsf-rt-display-time" reading_time="2"></span> <span class="bsf-rt-display-postfix" postfix="mins"></span></span><!-- .bsf-rt-reading-time -->

The Town of Arlington became the latest victim of a sophisticated cybercrime known as a Business Email Compromise (BEC) attack.  

The town suffered a financial loss of $445,945.73 due to fraudulent wire transfers orchestrated through phishing, spoofing, and social engineering tactics. 

A Business Email Compromise (BEC) attack is a form of cybercrime that targets organizations or individuals who conduct financial transactions through email. The attackers use various methods, such as phishing, spoofing, or social engineering, to compromise legitimate email accounts and impersonate trusted parties.  

They then send fraudulent requests for payments or transfers of funds, usually to offshore accounts. BEC attacks are often sophisticated and hard to detect, as they rely on human deception rather than technical vulnerabilities.  

“In September of 2023 Town employees received legitimate emails from a known vendor 

working on the Arlington High School Building Project to discuss issues with payment 

Processing,” a letter from Arlington Town Manager Jim Feeney said.  

The perpetrators, believed to be part of a well-known group, manipulated email communications to redirect four monthly payments into their accounts. The fraudulent activity spanned from September 2023 to January 2024. 

In response to the incident, Arlington's IT Department took swift action, implementing forced network disconnection, mandatory password changes, and multi-factor authentication.  

To further bolster cybersecurity, Arlington has mandated staff training through the state's Municipal Cybersecurity Awareness Grant Program and is in the process of deploying endpoint detection and response to safeguard against malware and ransomware threats. 

Arlington's experience serves as a stark reminder of the pervasive nature of cyber threats. The town's proactive measures and commitment to continuous adaptation of its defenses exemplify the necessary steps to mitigate the risks of future cyberattacks.