People potentially hit by a data breach were notified by the city of Roanoke by letter in late August — over three months after the fact — of the possibility that their personal information had been accessed in early May.
Mel Williams, a Roanoke attorney, received the letter from the city dated Aug. 24 that said that “on or about” May 11, the city found that on May 6 a “malicious actor gained unauthorized access to departmental data.” The letter does not identify the department or any other specifics about the hack. Nor did it disclose how many people could have been affected.
The city did not respond to numerous submitted questions about the incident Wednesday or Thursday.
Williams said the city waiting months to tell affected residents is “unconscionable” — “Why bother after waiting so long,” he said in an email. Williams said Thursday that he is not aware of any adverse effects so far.
“The malicious actor’s access was terminated soon after it was detected, but was able to gain access to a limited set of departmental data from the City’s network before being detected,” said the letter, which Williams provided to Cardinal News.
The city’s letter goes on to say that the following may have been accessed: first and last names, Social Security numbers, passport numbers and financial account information.
“We are providing this notice out of an abundance of caution,” the letter said. It added that to date, the city has not received any indication that personal data had been misused.
Williams said he has concerns that the hacker had five days of uninterrupted access before the city noticed the breach.
“Is there a worse scenario than having this connected information put in the hands of nefarious individuals?” he said by email.
“Upon discovering the incident, information technology experts were immediately engaged and commenced an investigation to determine the nature and scope of the incident,” the letter said. The city also reported the attack to the FBI.
The letter said the city engaged a “leading security service provider” to monitor the network, review the system’s architecture and implement stronger policies to prevent future attacks.
According to Virginia law, if “unencrypted or unredacted personal information” is “reasonably believed” to have been accessed by an unauthorized individual, the entity responsible for that data must disclose the breach to the state Office of the Attorney General and any affected resident of Virginia “without unreasonable delay.”
The statute says the notice may be “reasonably delayed” to allow the entity to determine the scope of the breach and restore the system first or if the breach is a matter of national security. It also says the attorney general can impose a civil penalty of up to $150,000 for an information breach.
Bruce Wetterau, who also received the city’s letter, said via email that he, too, is upset that the city waited three months to notify him and that it did not offer any identity theft protections.
“The letter just included a page and a half of general self-help tips I should take,” Wetterau said. Wetterau said he is also not aware of any adverse impacts from the breach.
For anyone with questions, the city in its letter recommended reaching out to its community engagement team.

