WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 Click2Gov – The Breach that Keeps on Breaching: More Utilities Impacted by Click2Gov Breach (including at least one WaterISAC member)
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Click2Gov – The Breach that Keeps on Breaching: More Utilities Impacted by Click2Gov Breach (including at least one WaterISAC member)

Author: Jennifer Walker

Created: Tuesday, December 10, 2019 - 19:24

Categories: Cybersecurity

WaterISAC previously posted the woes regarding Click2Gov on several occasions – view the Security & Resilience Update for November 21, 2019 for a listing of the three other posts. Likewise, a quick Google search reveals many more impacted municipalities and utilities, some having been affected more than once. With this recent spate of disclosures, WaterISAC is aware of at least one member who has been negatively impacted. This widespread event represents a significant issue regarding vendor/supplier/service provider risk. Furthermore, given malicious actors increase in the targeting of MSP’s (Managed Service Providers) to gain a foothold and then cascade into their client bases, it is imperative that members evaluate, assess, and carefully manage third-party relationships/contracts.

Incidentally, Click2Gov has not been the only online payment provider used by state and local government agencies to suffer in the past year. In September 2018, Brian Krebs reported GovPayNow.com leaked more than 14 million customer records dating back at least six years, including names, addresses, phone numbers, and the last four digits of the payer’s credit card.

Given the extent of the Click2Gov impact and potential for a higher than normal volume of members to be affected, WaterISAC will be providing a more critical analysis report in the near future. However, members wishing to know more may contact WaterISAC with an RFI. Likewise, to help WaterISAC more effectively track the impact from the Click2Gov breach, we encourage any water or wastewater utility (member or non-member) to complete a confidential incident report or contact WaterISAC at an*****@*******ac.org or (866) H20-ISAC.

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar