Supply chain β›“ Supply Chain

The Indio Water Authority Third-Party Breach (October 2018)

πŸ“… 2018-10-01 🏒 Click2Gov
Primary Source β†—

Incident Details

Another Click2Gov data breach hits Indio, California | StateScoop. The online bill payment software used by hundreds of local governments continues to be a frequent source of cybersecurity incidents. Residents of Indio, California, who pay their water bills online became the latest group of people whose personal identifying information was potentially exposed thanks to a vulnerability in Click2Gov, an municipal bill-payment program that has been connected to more than a dozen data breaches in small and midsize cities across the country since July 2017. Third-party company: Click2Gov.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Click2Gov
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2018-10-01 Breach occurred
  2. 2018-10-15 Publicly disclosed