County staff briefed the joint committee on an unauthorized disclosure on June 4 in which an Excel workbook containing multiple worksheets—including names, bank account and routing numbers and, for some volunteers, mailing addresses—was inadvertently distributed to six county email accounts and 62 volunteer leaders. Susan Farag said the incident "did not involve any type of cyberattack or compromise to a county system. Rather, it was a human error." She said the county has "no evidence that this information has been misused."
Deputy Chief Administrative Officer Forte Bekesy and IT leadership described the response. Bekesy said the county acted quickly: within roughly 1.5–2 hours the original email and copies were removed from county Exchange mailboxes and staff worked to delete more than 3,300 messages that could contain the data. Officials separately notified the 11 external volunteer recipients and asked them to delete the email, and the county issued both email and mailed notices to affected individuals where an email address was not available.
Keith Young, the county's information security officer (TEBS), said the workbook was created in payroll/finance during the transition from paper checks to electronic direct deposit for volunteer reimbursement. He described planned safeguards: stronger checklists and supervisory approvals for nonstandard reports, data classification and suppression in the ERP system to prevent exporting full bank numbers, tightened permissions and access controls, and investment in data loss prevention tools that can flag bulk account numbers prior to sending.
Members asked about outreach and support for retirees and volunteers. Officials said the county provided FAQs, call scripts and escalations for 311 so callers could be routed to retirement specialists and that division leadership attended a retiree association meeting to explain the incident. On the question of whether banks could block unauthorized ACH debits, officials said banks and account arrangements vary; county guidance included options such as changing account numbers or working with banks to set limits where available.
IT staff noted that encryption alone would not have prevented the human error because encrypted messages could still be opened and forwarded by authorized external recipients; they said the county lacks visibility into what happened to messages after they left external inboxes. Officials acknowledged tradeoffs in giving volunteers county email accounts for better control—the step is possible but administratively and financially costly—and said they will examine options further.