Back to overview
Confidence MediumMay 22, 2026aurora-il.org

City of Aurora loses $1.1M in phone scam cyber attack

PatternExternal actor · Social · Confidentiality impact

The City of Aurora lost approximately $1.1 million from city bank accounts after an employee fell victim to a phone-based social engineering scam. Attackers gained access to city bank account information and fraudulently transferred public funds.

Signal date
May 22, 2026
Updated
Jun 24, 2026
Confidence
Medium
Sources
2 sources
aurora-il.org logo

Aurora Il

Sector
Finance and Insurance
Signals
1 linked

Signal context

First seen: May 22, 2026

Last updated: Jun 24, 2026

Status: Public signal

Key points

  • City of Aurora lost $1.1 million.
  • Employee fell for a phone-based social engineering scam.
  • Attackers gained access to city bank accounts.

Signal analysis

Beta

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Affected organization
Aurora Il logo
Aurora Il

Sector: Finance and Insurance

Likely country: Location not provided

Estimated
Threat source
Social activity

The feed marks multiple actor roles. Treat this as a review signal rather than a final attribution.

  • Source type: outside the affected organization
  • Source type: possible insider or internal misuse
Business impact
Potential fraud or account takeover risk

Impact area: Confidentiality

Likely asset: User or customer data

Trend context
7 signals with similar action pattern
  • 14 signals in the same sector
  • 66 signals with the same likely impact area
  • 1 signal linked to this organization/domain
Mentioned entities
Aurora IlData DisclosureCity of AuroraThe City of AuroraAttackersEmployee

External sources

Related signals

Grouped by why the signal is relevant.

irhythmtech.com logoIrhythmtechJun 8, 2026
Same sectorSame action patternSame impact area

iRhythm Holdings Identifies Data Breach via Third-Party Applications

iRhythm Holdings, Inc., a digital healthcare company, identified unauthorized activity on certain third-party-hosted business applications on June 8, 2026. A threat actor subsequently claimed to have obtained proprietary data, patient protected health information (PHI), and other personal information, demanding payment to prevent public disclosure. The company confirmed that some data was exfiltrated. The attack was attributed to social engineering. iRhythm stated that its clinical and medical device systems, patient safety, operations, and financial reporting systems were not affected, and no payment card or financial account data was involved.

sofi.com logoSofiJun 8, 2026
Same sectorSame action patternSame impact area

SoFi Hong Kong Confirms Third-Party Data Breach

SoFi Hong Kong, a subsidiary of the U.S.-based financial technology company SoFi, confirmed a data breach after unauthorized access was gained to a customer information database managed by a third-party vendor. The incident was detected on April 30, 2026, and publicly disclosed on June 8, 2026. The compromised data included names, dates of birth, addresses, email addresses, phone numbers, and employment and education information. The company stated that no account passwords or financial account numbers were reportedly exposed. The attack involved social engineering and exploitation of third-party vendor access. SoFi Hong Kong advised customers to remain vigilant for phishing attempts and suspicious activity.

xsolis.com logoXsolisJun 22, 2026
Same action patternSame impact area

Healthtech firm Xsolis suffers data breach impacting 1.4 million people

Healthcare technology company Xsolis disclosed a data breach affecting nearly 1.4 million individuals. The incident stemmed from a targeted phishing attack on January 20, 2026, which led to unauthorized access to a limited portion of the Xsolis environment. Attackers accessed files containing customer information, including names, addresses, dates of birth, health insurance information, Social Security numbers, and medical treatment information. Xsolis is a U.S.-based firm providing AI-powered software for healthcare organizations.

tpwd.texas.gov logoTpwdJun 19, 2026
Same sectorSame impact area

Texas Parks and Wildlife Department data breach exposes over 3 million driver's licenses

The Texas Parks and Wildlife Department (TPWD) disclosed a data breach at its license system vendor that exposed personal information for more than three million individuals. The compromised data included driver's license information, passport numbers, email addresses, phone numbers, and residential addresses. Social Security Numbers, dates of birth, or financial information were not impacted.

nintendo.com logoNintendoJun 18, 2026
Same sectorSame impact area

Nintendo confirms data stolen in WebMD subsidiary cyberattack

Nintendo of America confirmed that survey data was stolen from TinyPulse, a third-party service used internally for employee surveys. The company emphasized that its own systems were not compromised, and no personal customer or financial data was accessed. The data involved was limited to internal survey content from a small subset of employees, with most information dating back several years. The Shadowbyt3$ extortion group claimed responsibility, demanding a $2 million ransom.

americanexpress.com logoAmericanexpressJun 11, 2026
Same sectorSame impact area

American Express Insider Data Breach Reported

American Express was involved in an insider data breach where an employee accessed the personal financial information of an individual. An investigation by the Australian Privacy Commissioner found the company breached privacy laws by failing to implement adequate restrictions on staff access to customer accounts.