City of Aurora and Illinois: Aurora, Ill., Investigating Recent Cyber Attack

City of Aurora and Illinois: Aurora, Ill., Investigating Recent Cyber Attack

Aurora, Illinois Investigates Sophisticated Cyber Attack Resulting in Fraudulent ACH Payments

The city of Aurora, Illinois, is investigating a cyber attack that led to unauthorized ACH transactions from city accounts, discovered on April 30 just one day after the fraudulent activity occurred. Mayor John Laesch described the incident as a "very sophisticated cyber attack," though city officials maintain that internal systems were not compromised.

While the exact financial loss remains undisclosed, authorities, including the Aurora Police Department and the FBI, are actively working to determine the total amount stolen. The city has taken immediate steps to mitigate the impact, recovering some funds and expressing optimism about further recovery efforts. Aurora also holds insurance to cover such incidents.

The fraudulent transactions involved ACH (Automated Clearing House) payments, which require only a bank account and routing number commonly used for business bill payments. Due to the ongoing investigation, details about potential disciplinary actions, specific departmental involvement, or personnel matters have not been released.

Aurora has partnered with cybersecurity firm NuHarbor Security, Inc., and implemented employee training programs, including KnowBe4’s cybersecurity courses and regular phishing exercises. The city has not publicly disclosed the incident until now, citing the active nature of the investigation. Law enforcement and cybersecurity professionals continue to collaborate on the case.

Source: https://www.govtech.com/security/aurora-ill-investigating-recent-cyber-attack

City of Aurora, IL cybersecurity rating report: https://www.rankiteo.com/company/city-of-aurora_2

"id": "CIT1779294250",
"linkid": "city-of-aurora_2",
"type": "Cyber Attack",
"date": "4/2026",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'industry': 'Public Sector',
                        'location': 'Aurora, Illinois, USA',
                        'name': 'City of Aurora, Illinois',
                        'type': 'Government'}],
 'attack_vector': 'ACH Payment Fraud',
 'date_detected': '2024-04-30',
 'description': 'The city of Aurora, Illinois, is investigating a cyber attack '
                'that led to unauthorized ACH transactions from city accounts, '
                'discovered on April 30 just one day after the fraudulent '
                "activity occurred. The incident involved a 'very "
                "sophisticated cyber attack' with no compromise of internal "
                'systems, though the exact financial loss remains undisclosed. '
                'Authorities, including the Aurora Police Department and the '
                'FBI, are actively working to determine the total amount '
                'stolen.',
 'impact': {'payment_information_risk': 'High'},
 'investigation_status': 'Ongoing',
 'motivation': 'Financial Gain',
 'recommendations': 'Employee training programs (KnowBe4’s cybersecurity '
                    'courses, regular phishing exercises)',
 'references': [{'source': 'City of Aurora Official Statement'}],
 'response': {'communication_strategy': 'Limited public disclosure due to '
                                        'active investigation',
              'containment_measures': 'Fund recovery efforts, insurance '
                                      'coverage',
              'law_enforcement_notified': 'Aurora Police Department, FBI',
              'recovery_measures': 'Fund recovery efforts',
              'third_party_assistance': 'NuHarbor Security, Inc.'},
 'title': 'Sophisticated Cyber Attack on Aurora, Illinois Resulting in '
          'Fraudulent ACH Payments',
 'type': 'Financial Fraud'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.