Back to Princeton

Personal information was among data taken from city systems, Princeton says in breach update

Princeton officials said Monday a forensic review found confidential and personally identifiable information was removed from city systems; affected people will be notified and offered credit monitoring.

Gwen Mercer

October 6, 20262 min read

Locked server and data stream - illustration, Jake Team LLC

Princeton officials said Monday that information was taken out of city computer systems during the cybersecurity incident first disclosed in September, and that the data includes personally identifiable information.

In an update posted at 11:19 a.m. Oct. 5, the city said it determined that day that information had been exfiltrated. The material includes confidential records and personal information, according to the statement, which did not say what kinds of records were involved or how many people could be affected. The city said it is still working with cybersecurity specialists to establish the full scope.

A shift from earlier findings

The update marks a change from what the city reported two weeks ago. On Sept. 22, Princeton said two independent reviews had turned up no evidence of unauthorized access, a confirmed breach or data being removed, and that it was hiring a third firm for a full forensic review "out of an abundance of caution."

Monday's statement said earlier system scans and outside analysis had not shown at the time that personal information was compromised, but the ongoing forensic work later identified additional information that needed review.

What happens next

Once the review identifies which people and which records were affected, the city said it will notify them as required by law and offer resources including identity protection and credit monitoring. City services are running normally, the statement said.

The city first announced the incident Sept. 18, saying it had secured affected systems and was working with the Princeton Police Department, outside cybersecurity specialists and law enforcement partners. That statement also noted that information about the incident was circulating online and said the city would rely on its own investigation rather than claims from outside parties.

Breachsense, a site that tracks data breach claims, lists the City of Princeton as a victim claimed by the INC Ransom group, with a date of Sept. 17 and no leak size given. The city has not publicly named any group or confirmed that listing.

Media questions about the investigation go to Erin Mudie, the city's director of marketing and communications, at 469-307-8548.

Sources

princetontx.gov

breachsense.com

Share

Gwen Mercer

Gwen Mercer writes about community life, schools, public safety, and local events in Princeton.

Related Stories

More in Texas