CyberSecurity

Increase your government’s account security with multi-factor authentication

Strengthening your government's guard against the threats that compromised passwords pose is a necessary control for decreasing the risk of unauthorized users gaining access to your computers, network or database. In this post, we explain how passwords get compromised and how multi-factor authentication (MFA) can help governments improve their account security to better protect their systems.

How passwords get compromised

A message from State Auditor Pat McCarthy: Cybersecurity is a shared responsibility

It can be tempting to think it's the experts' job to keep us safe online. We trust our colleagues who are IT professionals and the technology services we use to stay up to date on the latest threats. But all of us, whether or not we are technology experts, have a part to play in cybersecurity. That's why this year's theme for October's Cybersecurity Awareness Month is “Do your part, #BeCyberSmart.”

Vulnerabilities in federal law, gaps in state fraud detection led to losses in unemployment insurance program, audits find

OLYMPIA – Emergency federal unemployment programs launched early in the COVID-19 pandemic included provisions that opened state unemployment benefits to fraud, the Office of the Washington State Auditor found in three audits released today.

While Washington was not alone in being targeted, the state Employment Security Department continues to struggle in answering customer questions, investigating suspected fraud and retrieving important data from its systems, the audits found.

Third-party service provider’s security incident compromised Washingtonians’ personal information

A security incident involving a third-party provider of hosted software services, which was used by the Office of the Washington State Auditor, might have exposed sensitive data belonging to Washingtonians.

This data includes personal information from about 1.6 million unemployment claims made in 2020, as well as other information from some state agencies and local governments.

SAO making our outgoing emails cyber-safer

The State Auditor's Office is changing some of the emails we send every week to better align with cybersecurity best practices.

Beginning the week of Nov. 9, emails we send related to the publication of audit reports no longer will contain attachments nor embedded links. We are working to reduce the number of potential targets for attack by cyber-criminals while maintaining timely communication with you.

Email messages that alert recipients when we publish reports will now have two features:

Has your government experienced a cybersecurity issue? Here is when and how to report

Some security breaches are required to be reported to the Washington State Attorney General's Office (AGO), and sometimes you need to report various cybersecurity issues to the State Auditor's Office, too! Of course, we hope you have none, but if you find yourself in this spot – here is some important information that can help you comply with law.

Reporting to the Attorney General

How to prevent ACH and bank fraud

Welcome to readers who found their way here during the 2021 International Fraud Awareness Week! We first posted this article in September 2020, and the threat of bad actors diverting paychecks or vendor payments remains acute since so many of us are working remotely and doing business electronically. Please take a moment to understand how these schemes work, and consider our tips on how to protect your organization.