Kentucky Association of Counties

KACo Logo

Kentucky Association of Counties

County email accounts can be a target for hackers

Be cautious if an email asks for a PDF passcode or to click a link
Recent incidents involving compromised county government email accounts are an important reminder that email remains one of the easiest ways for cybercriminals to gain access to county systems, information and financial resources.

A compromised email account can be particularly dangerous because messages sent from a legitimate county employee’s account may look completely normal. An attacker can review previous conversations, learn how an employee communicates and then use that trusted account to target coworkers, vendors, other counties or members of the public.

That means everyone has a role to play in protecting county systems.

Be suspicious, even when you recognize the sender

Phishing emails aren’t always obvious. In fact, some of the most convincing attacks come from real accounts that have already been compromised.

Be especially cautious if an email:
  • Unexpectedly asks you to click a link, open an attachment, use a PDF passcode or sign into an account.
  • Requests a payment, wire transfer, change in banking information or purchase of gift cards.
  • Asks you to provide a password, verification code or other sensitive information.
  • Creates unusual urgency or pressure to act immediately.
  • Comes from someone you know but doesn’t sound quite like them.
  • Continues an existing email conversation but suddenly introduces a new payment request, attachment or link.
  • Directs you to a Microsoft 365, Google or other login page after clicking a link.
  • Asks you to approve a multifactor authentication (MFA) request you did not initiate.
When something seems unusual, verify it another way. Call the sender using a phone number you already have, not a number provided in the suspicious email.

Steps counties can take now

Require MFA on county email accounts

Multifactor authentication provides an additional layer of protection when a password is stolen. Counties should require MFA wherever possible, particularly for email, remote access and administrator accounts. Stronger methods such as security keys or authenticator applications provide greater protection than text-message codes.

Review email accounts and access

Administrators should review accounts for suspicious sign-ins, unexpected forwarding rules, unfamiliar devices and other unusual activity. Disable accounts that are no longer needed and limit administrative privileges to employees who actually require them.

Strengthen email security

Counties should work with their IT staff or technology providers to ensure spam and phishing protections are properly configured and that email authentication protections are in place.

Keep systems updated

Apply security updates promptly to operating systems, browsers, email applications and other software. Attackers frequently exploit known vulnerabilities that already have fixes available.

Train employees and make reporting easy

Employees should know how to recognize suspicious messages and, just as importantly, exactly how to report one. A quick report to IT or an administrator can help protect the rest of the organization if similar messages are being sent to multiple employees.

Protect financial transactions with procedures, not just email

Counties should never rely solely on an email to authorize changes to banking information, electronic payments or other significant financial transactions. Establish a separate verification process, such as calling a known contact using previously established contact information.

If you think an account has been compromised:

Act quickly. Contact your IT department or technology provider immediately. The account’s password should be reset, active sessions reviewed or terminated, MFA settings checked, and email forwarding rules and recent activity examined.

If you receive a suspicious email from another county employee or government official, don’t assume that person intentionally sent it. Their account may have been compromised. Contact them through another method and alert your IT staff.

Cybersecurity isn’t solely an IT responsibility. A single employee recognizing that something doesn’t look right and reporting it before clicking can prevent a much larger incident.

When in doubt, don’t click. Verify first.


More County News