DE Kalb County, Indiana has fallen victim to a vendor impersonation billing scheme, marking a second cybersecurity incident for the county in just over a year. The Star reports that on 1 October 2026, a financial payment was made after an employee was deceived by an email that impersonated a vendor asking for payment.
A multi-agency response team – comprising County Commissioners, County Attorney, Information Technology, Treasurer’s Office, Auditor’s Office, and Emergency Management/Homeland Security – assembled to manage the incident and began efforts to recover the funds. The county has since recovered most of the payment and continues to attempt recovery of the remaining sum.
The article notes that the 2025 incident, which The Star also references, involved a data breach with potential exposure of residents’ personal information. A notice in March 2026 described an incident dating back to August 2025 that affected residents’ data, including combinations of names with one or more of Social Security numbers, driver’s licence numbers equivalent, and financial account numbers.
While the newer October 2026 event appears to be financial fraud rather than a data exfiltration breach, the county’s authorities emphasise ongoing investigation and recovery efforts. The report attributes the information to a DeKalb County emergency management news release and local reporting, with the situation described as a phishing-based intrusion leading to a payment that was later detected.