Hackers steal personal data including credit card information of ~300K people across 46 cities, using a vulnerability in government payment software Click2Gov
Paying parking tickets or municipal water taxes is never fun—and it's even worse when hackers have compromised your town's payment system.
Context & Ripple Effects
Municipal online-payment systems keep turning out to be soft targets. Just two months before this story, GovPayNow.com — used by roughly 2,300 US government agencies had left more than 14 million customer records exposed dating back to 2012, and weeks later a system feeding HealthCare.gov was breached, compromising data on about 75,000 people.
The Click2Gov incident raises the stakes because of its structure: one vendor's payment software is deployed across hundreds of city halls, so a single vulnerability converts into simultaneous card theft for ~300,000 people in 46 cities rather than one town's problem.
First-order effects
- Residents across 46 cities who paid parking tickets or water bills through Click2Gov portals now have credit card and personal data in attackers' hands, and each affected municipality must run breach notification and card-replacement fallout for transactions its own staff never touched.
- The software vendor behind Click2Gov faces its entire installed base questioning whether the same flaw exists in their deployments.
Second-order effects
- Other cities running shared government payment platforms — the GovPayNow model among them — are pushed toward vendor security audits and contractual liability clauses before renewal, shifting procurement criteria from price to breach exposure.
- Card issuers absorb the fraud cost, reinforcing the economics that make bulk dumps like the 5.3M+ account cache tied to compromised Hy-Vee pumps and restaurants profitable enough to keep attackers targeting high-volume, low-defense payment endpoints such as ParkMobile.
Third-order effects
- If the pattern holds, local-government payment infrastructure consolidating into a handful of vendors makes each vendor a systemic single point of failure, likely drawing state-level procurement standards or federal attention to municipal cybersecurity the way the HealthCare.gov-adjacent breach did for health data brokers.
The trend: As US local governments outsource payments to a small set of common vendors, one unpatched vulnerability now breaches dozens of cities at once, making vendor security a de facto public-infrastructure issue.