Boone County Employees Impacted by DCS Data Breach Exposing SSNs
The Indiana Department of Child Services (DCS) is investigating a data breach after inadvertently exposing the personal information of 290 Boone County employees. On July 21, a DCS employee forwarded an email containing a spreadsheet with employees’ names and Social Security numbers to unintended recipients, including four Boone County employees and two external vendors.
The breach occurred during an annual audit tied to federal funding, where DCS requested employee data from Boone County’s Auditor’s Office. The document, intended for internal use, included sensitive information that should not have been shared. Boone County IT acted quickly to recall the emails from employees and contacted the vendors to prevent further dissemination.
DCS acknowledged the incident, stating it is following state and federal breach notification protocols. Boone County is pushing for identity-theft protection and credit-monitoring services for affected employees. The agency has not disclosed the cause of the unauthorized forwarding but confirmed an investigation is underway. Employees were advised to monitor their credit reports and financial accounts for suspicious activity.
Source: https://www.wishtv.com/news/i-team/boone-county-employee-ssn-leak/
Lebanon School Corporation Transportation cybersecurity rating report: https://www.rankiteo.com/company/boone-county-government
Indiana Department Of Child Services cybersecurity rating report: https://www.rankiteo.com/company/department-of-child-services
"id": "BOODEP1784932088",
"linkid": "boone-county-government, department-of-child-services",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '290 employees',
'industry': 'Public Sector',
'location': 'Indiana, USA',
'name': 'Boone County',
'type': 'Government (County)'}],
'attack_vector': 'Human Error (Email Misdelivery)',
'customer_advisories': 'Employees advised to monitor credit reports and '
'financial accounts for suspicious activity.',
'data_breach': {'file_types_exposed': 'Spreadsheet',
'number_of_records_exposed': '290',
'personally_identifiable_information': 'Names, Social '
'Security Numbers',
'sensitivity_of_data': 'High (Social Security Numbers)',
'type_of_data_compromised': 'Personally Identifiable '
'Information (PII)'},
'date_detected': '2023-07-21',
'description': 'The Indiana Department of Child Services (DCS) is '
'investigating a data breach after inadvertently exposing the '
'personal information of 290 Boone County employees. A DCS '
'employee forwarded an email containing a spreadsheet with '
'employees’ names and Social Security numbers to unintended '
'recipients, including four Boone County employees and two '
'external vendors.',
'impact': {'brand_reputation_impact': 'Potential reputational damage to DCS '
'and Boone County',
'data_compromised': 'Names, Social Security Numbers',
'identity_theft_risk': 'High risk of identity theft for affected '
'employees',
'legal_liabilities': 'Potential legal liabilities under state and '
'federal breach notification laws'},
'investigation_status': 'Underway',
'post_incident_analysis': {'root_causes': 'Human error (unauthorized email '
'forwarding of sensitive data)'},
'recommendations': 'Implement stricter data handling policies, employee '
'training on sensitive data sharing, and automated email '
'filtering for PII.',
'references': [{'source': 'Incident Report'}],
'regulatory_compliance': {'regulations_violated': 'State and federal breach '
'notification protocols',
'regulatory_notifications': 'Following state and '
'federal breach '
'notification '
'protocols'},
'response': {'communication_strategy': 'Advising employees to monitor credit '
'reports and financial accounts',
'containment_measures': 'Email recall, vendor contact to prevent '
'further dissemination',
'remediation_measures': 'Identity-theft protection and '
'credit-monitoring services proposed'},
'title': 'Boone County Employees Impacted by DCS Data Breach Exposing SSNs',
'type': 'Data Breach'}