YAMHILL COUNTY, Ore. — After a cyberattack released some McMinnville residents’ personal information, Newberg and Dundee officials said any city could be a target.
On Sept. 30, the city of McMinnville notified residents that a cyberattack revealed in July may have exposed their names, driver’s license numbers, and Social Security numbers on the internet, according to the News-Register in McMinnville. The hacking group RansomHouse claimed responsibility for the attack, which released the information on the dark web.
According to cybersecurity firm CrowdStrike, the dark web is a part of the internet where users can access unindexed web content, or web content that does not appear in search engines, anonymously through special web browsers.
On Sept. 22, the McMinnville City Council approved a three-year, $1.28 million cybersecurity contract with VC3 that will provide threat detection and supplement the efforts of the city’s IT department, according to the News-Register.
Cyberattacks can take many forms, usually by accessing computers, mobile phones, and other internet-connected devices, according to Ready.gov. That access could give attackers entry to sensitive files, financial accounts, and personal information, or allow them to gather sensitive or incriminating information to solicit ransom. On larger scales, cyberattacks could damage or interrupt civic infrastructure.
“Any city could fall victim to this kind of attack,” said Newberg City Manager Will Worthey. “What matters is how a city prepares for it in the first place. There are no guarantees anymore.”
Worthey said the city cannot disclose all of its cybersecurity systems, tools, and protocols because keeping them unknown to the general public is a layer of security. However, he said the city employs a multi-layered cybersecurity defense strategy to protect internal systems and data.
“While no organization is 100% immune against increasingly sophisticated threats, we treat cybersecurity as an ongoing daily operational responsibility,” Worthey said in an email.
He said the McMinnville cyberattack was a reminder to the city’s team, led by IT Director Dave Brooks, of the importance of cybersecurity practices. Worthey called the team “the immune system of our city.”
“While they don’t often engage with the public, the policies and procedures they follow keep our city’s and residents’ data safe and secure,” he said.
Dundee City Administrator Courtney Patterson said the city has outsourced IT and cybersecurity and changed vendors Sept. 1, which prompted a cybersecurity analysis.
“Cities are a known target for cyberattacks, so it’s just something that we regularly keep in mind and make sure that our team completes annual cybersecurity training,” Patterson said.
Protect Yourself Against Cyberattacks
Ready.gov recommends that people limit the personal information they share online and not use location features on browsers or social media apps. The site also recommends keeping applications and operating systems up to date and using strong alphanumeric passwords with special characters for every website.
Users can also use two-factor authentication, which adds an extra layer of security by requiring a verification code sent through another method of communication before granting access to an account.
Phishing attacks are common, harmful emails disguised as transactional messages that may look as if they were sent from a trusted brand or company. These emails usually have malicious links that prompt users to enter usernames and passwords, which scammers will use to access the real accounts online.
“Watch for suspicious activity that asks you to do something right away, offers something that sounds too good to be true, or needs your personal information,” Ready.gov’s cybersecurity page said. “Think before you click. When in doubt, do NOT click.”
The guide also recommends that people use secure internet connections, change passwords regularly, not share PINs or passwords, check account statements and credit reports consistently, and not share personal financial or credit information when in doubt. According to the guide, governments will not call, text, or contact people through social media about owing money.
The guide also recommends backing up files regularly in an encrypted file or on an encrypted file storage device.
Learn more at Ready.gov’s cybersecurity guide web page.
Community-supported journalism
This article was made possible by the generous support of Newsberg readers and advertisers. Independent local news takes real resources to produce. If Newsberg is valuable to you, please consider joining us — for as little as $1 a month, or with a one-time gift in any amount.