The City of Princeton is investigating claims that a ransomware group targeted its IT systems and stole sensitive information.
The group is claiming responsibility, but Tuesday night, the city said two independent cybersecurity reviews have found no evidence of unauthorized access.
In a statement, the city said, “Based on the information currently available, neither review has identified evidence indicating unauthorized access to City systems, a confirmed data breach, or unauthorized data exfiltration.”
The city says it’s still investigating.
But online, a ransomware group claims it got deep inside city systems, according to Matt Barnett with the cybersecurity firm SEVN-X.
“They are claiming to have a complete backup of the city’s internal file server, which contains over 20 departmental folders spanning every branch of municipal operations,” Barnett said.
He says that includes, according to the group’s post, nearly two gigabytes of data, more than 13,000 residential addresses, more than 2,500 new residential accounts, delinquent accounts, credentials to city systems, court records and forensic copies of devices including the mayor’s phone.
Barnett says the group gives the city 10 days to make contact before full publication begins.
“So before the data is released, they’ll put out snippets or claims of what they do have,” Barnett said.
One of the first steps, he says, is determining whether the attackers really have the data they claim, which is known as “proof of life.”
During a special meeting Monday night, citing an intrusion into critical IT and communication systems, the mayor responded to a resident who asked to hear more about how and why it happened. “Are we still at risk?” the man said.
Mayor Eugene Escobar Jr. responded, “As of today, there has been no evidence that anything posted online is actually accurate. So, about a breach or anything, but that’s all I’m going to say about that.”
The city says its investigation is underway and so far, has not found that information was stolen or affected.
“Having negotiated ransomware payments for a living, I’ve rarely seen that a threat actor will say they have something that they can’t later verify,” Barnett said. “But again, without having access to the investigation or being part of the internal, I wouldn’t know exactly what’s affected.”
For now, the city says essential services will continue while they work to determine what happened.
