County staff briefed the joint committee on an unauthorized disclosure on June 4 that involved an Excel workbook containing four worksheets used during a direct-deposit transition. The spreadsheet inadvertently included too much payroll information and was emailed to internal staff and to 62 volunteer fire-and-rescue leaders; the county estimates roughly 7,500 county retirees, career staff and some volunteer firefighters were affected.
Deputy Chief Administrative Officer Foyueva Kisir and finance staff said the incident resulted from "human error," not a cyberattack, and that the county moved quickly to contain the disclosure. Staff reported the email and copies were removed from county Microsoft Exchange mailboxes within about 1.5–2 hours of notification and that a secondary deletion sweep removed more than 3,300 messages that might have contained the data. External recipients (11 volunteer chiefs/presidents not on the county email system) were contacted within four hours and asked to delete the message.
The county notified affected individuals within four days by email or postal mail and provided FAQs and call scripts to 311 and to a retirement division hotline. Officials said the disclosed fields included bank name, routing number and account number (and, for some volunteers, mailing address) but did not include Social Security numbers. The county reported no evidence to date that the information has been misused.
Committee members pressed staff for additional steps, including internal audits of new processes, stronger direct outreach to retirees without email, masking or suppression of bank details in exports, and consideration of issuing county-domain email addresses for volunteers. IT staff said they are expanding data-classification, email-suppression and data-loss-prevention techniques and will explore targeted audits and additional controls.