August 2025 News & Tips | City of St. Paul Data Breach & Understanding AI

August 2025 News & Tips City of St. Paul Data Breach & Understanding AI
View this email in your browser
The mission of this publication is to cut through the clutter of cybersecurity news stories and provide you with the most important, relevant and actionable cybersecurity information.

If this newsletter adds value, fantastic! That is the goal. Please forward it on to friends/colleagues. If not, no hard feelings. Please look to the bottom for an easy to click "unsubscribe" button.
Subscribe
In this issue:
Month's News in Review
Upcoming Speaking Events
TCE Strategy in the News
Must Read Articles This Month
Cybersecurity Tip of the Month
Enjoy this month's newsletter? You can use this link to post on social media or send to friends! Thanks for sharing!
This Month's News in Review

Welcome back to the monthly TCE Strategy newsletter! August has had enough cybersecurity issues to fill a 100-page book, let alone a newsletter. I had to be very picky about which stories to cover. Suffice it to say, if the next few months are totally devoid of cybersecurity news, I have enough material to make it into the new year. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.

 

City of St. Paul breach causes widespread outages of critical services.

The City of St. Paul, Minnesota, USA woke up to a serious issue Friday, July 25th. An intruder was discovered in their network. The City spent the weekend trying to understand the scope of the problem, and it was much larger than any sort of cyber issue they had dealt with previously. On Monday, July 28th the city shut down most of its key systems. City Wi-Fi was cut. Fire and EMS Computer Aided Dispatch (CAD) systems—critical for detailed dispatching, GPS navigation, incident updates, and more, were taken down. The laptops that police officers use in their squad cars were disconnected (this technology has been available since the late 1970’s, so it’s a very well established part of police work). Payment systems were cut – cash only for everything from paying your water bill to getting your car out of impound. Police dispatch was moved to manual backup procedures. The city called in the National Guard, the FBI and two private cybersecurity remediation companies. The governor of Minnesota declared and extended a “state of emergency” for 90 days. This was bad.

It turned out that the Interlock ransomware gang got into the St. Paul Parks and Recreation system, exfiltrated 43GB of data (that’s a lot), and likely encrypted the data on St. Paul’s systems as part of a ransomware attack. I’m guessing that the amount of access that the ransomware gang had in the system was extensive, and I’m guessing that the Parks and Recreation system shares networks, applications, and user accounts with other parts of the City of St. Paul. That’s likely why the city took most of their systems offline on Monday the 28th.  

Recovery has been slow. No systems were restored until August 11th, and a full recovery is still “weeks away.

For citizens of the City of St. Paul, this has been more than an inconvenience. If City Wi-Fi is your only means to get on the Internet, losing that service is very meaningful. If your car is impounded and the City can’t take your check or credit card, that is very meaningful. If you are in need of police, EMS or fire services and their arrival is delayed because Computer Aided Dispatch systems are down, that is very meaningful. From a services standpoint, hopefully things are put back to normal soon.

From a data standpoint, the cat is completely out of the bag. The City refused to pay the ransom (and kudos to them for that), but the Interlock ransomware gang chose to release all the data they stole. Most of it is not overly sensitive data, but some of it genuinely is: my team looked through it, and we found the W2 for the Director of Parks and Recreation for the City of St. Paul, among others. We found the medication sheets for kids that have attended summer camp for the last 10 years. We found several documents containing passwords (it is unknown if these are active usernames/passwords or old ones). Not good. It’s genuinely surprising to me that the disclosure of this confidential information didn’t get more press coverage. Perhaps because the number of records was far lower than other breaches, it wasn’t as strong a headline story? Perhaps there have been so many data breaches that we are becoming numb to them? No matter the reason, it’s sad to see that more coverage wasn’t given to the victims of this data breach.

Takeaway: Ransomware is a preventable crime! It’s terrific that the City of St. Paul had strong data backups, but that doesn’t make whole the people who rely on city services but couldn’t receive them, nor those whose confidential data was released to the whole world strictly out of spite. We need to take proactive ransomware prevention more seriously.

 

Understanding how to use something is not the same as knowing how something works.

It’s counterintuitive to think that most people use things everyday that they don’t fully understand how they work. This isn’t a new issue. Humans have been using fire since before recorded history, but understanding the concepts of combustion (the use of oxygen to chemically interact with a fuel source to release heat, carbon dioxide and water) has only come in the last few hundred years. Gregor Mendel is recognized as the founder of genetics – he discovered dominant and recessive genetic traits (he called them “heritable factors”), but had no understanding of DNA or genes. Madam Curie discovered the incredible usefulness of radiation, but did not understand the potentially harmful effects that radiation can have, and ultimately it was radiation that killed her. The understanding she needed to use radiation safely didn’t come until decades later.

The 2020’s technology scene is being completely dominated by advances in AI, which I use often. It does a terrific job researching a subject and providing a Cliff Notes (or Spark Notes for our younger readers) version of the topic. It is extremely useful in the kitchen for recipes. It is moderately useful at writing code, although I’ve had times when it takes more effort to get the AI engine to understand what I’m looking for than it would be to code things myself. AI tries to be helpful. It is pleasant. It is complimentary. It is also not completely understood how it actually works. In fact, there are some recent articles that propose the idea that as our AI models get more and more complex, we are in fact losing ground in our understanding of how they work.

We have a fundamental issue here: When technologies are put into place without a complete and thorough understanding of how they work, negative consequences can occur. Grain mills have exploded because the dangers of grain dust as a source of combustion were not well understood. We lost 3 astronauts in the Apollo 1 ground fire in 1967 because the dangers of fire in a pure oxygen atmosphere were not well understood. Now we are living in an age of AI where it is successfully taking a surprising amount of “grunt work” or entry-level positions out of the hands of people and into those of a computer. The problem is that we don’t fully understand how it works. We just know that it’s useful. I wrote last month about how AI is sometimes too nice and can support ridiculous theories. This month, the Wall Street Journal doubled-down on their reporting about that issue, stating that AI is fueling delusional spirals for some of its users, with the primary issue seeming to be a disconnect between AI’s interest in getting a question correct vs. its interest in making the user of AI feel good about him/herself. 

There seems to be an overwhelming desire on the part of AI users for AI to be “friendly” for lack of a better term. OpenAI rolled out ChatGPT 5 this month, and there are lots of reports about how it had a “diluted personality”. A Reddit group has spawned specifically to lambast it. So, OpenAI is working to make it more friendly.  I think we are likely to see much more of these “two steps forward one step back” moments in the world of AI, as we don’t really know how it works, so the results it gives are unpredictable. This is to be expected for some time, likely for years to come.

Takeaway: AI is not your friend. Using it to make you feel better will lead to a fool’s paradise. Expecting it to make you feel better about yourself is a bad idea. If anything, having it be a little adversarial when it comes to new ideas isn’t the worst idea. Some of the best science comes from slightly adversarial premises.

 

Until next month, stay safe!

Upcoming Speaking Events


Here is a list of the cities that I will be in over the next several months. Please reach out if you have an event in mind!


September 8-10, Rochester, MN

October 21-23, Detroit, MI

October 29-30, Boston, MA

December 1-5, Key West, FL

December 11-15, Phoenix, AZ

December 22-26, Ft. Myers, FL

March 8-17, 2026, Cairns, Australia

TCE Strategy in the News

Thank you to Raya Quttaineh and the KARE11 team for the opportunity to be interviewed about the City of St. Paul data breach.

Interesting Articles

It is so sad and frustrating to see corruption like this. Kickbacks to people that specialize in ransomware negotiations. I hope this gets prosecuted. "This moral hazard has been present for years and has manifested itself several times, but it's always the same underlying issue. If an intermediary earns a large fixed percentage of a ransom, objective advice is not going to follow."
Can someone explain to me why the Feds wouldn't want funds to go to the MS-ISAC (Multi State Information Sharing and Analysis Center)? Most of my clients have told me that the ISACs are genuinely useful cybersecurity information sharing platforms. I'm confused here...
Cybersecurity Tip of the Month

Stop Fraud Before It Starts: Freeze Your Credit

With major data breaches continuing to make headlines in 2025, now is a great time for a refresher on freezing your credit. Concerned about someone opening a credit card or loan in your name? That’s a valid worry, but it’s also one you can largely avoid by placing a credit freeze with the credit bureaus that manage your data. The three biggest are Experian, TransUnion, and Equifax. It is now free to freeze and unfreeze your credit (they used to charge for this “privilege” of keeping yourself safe, similar to how phone companies used to charge for not publishing your name in the phone book. Pure robbery.).

There are a few drawbacks. It can be inconvenient to lift a freeze when you actually want a new loan or credit card. Credit checks also pop up in less obvious situations, like switching mobile carriers or setting up new utilities (electric, water, gas, etc.). Still, for most people, the protection outweighs the hassle, especially since it’s now quick and free to manage your freeze.

To set one up, you’ll need to contact each of the three major consumer credit bureaus (Equifax, Experian, and TransUnion) and request a credit freeze. You’ll provide your name, address, date of birth, and Social Security number, then answer identity verification questions. Each bureau will issue you a PIN or password to use when unfreezing or refreezing your credit report. By federal law, this service must be offered at no cost.

LinkedIn
Twitter
Facebook
Website
Forward Forward
We want your feedback!

< On a scale of 10, how helpful was this newsletter?>

lowest 1   2   3   4   5   6   7   8   9   10   highest

Copyright © 2025 TCE Strategy, All rights reserved.
You are receiving this email because you are on Bryce Austin's contact list

Our mailing address is:
TCE Strategy
18268 Java Trl
Lakeville, MN 55044

Add us to your address book


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list

You can reach Bryce at bryce@bryceaustin.com

Email Marketing Powered by Mailchimp
Subscribe to Newsletter

Browse newsletter archives: