KSL INVESTIGATES

Documents reveal financial fallout of Salt Lake City IT security breach

Mar 31, 2022, 10:02 PM | Updated: Jun 18, 2022, 8:29 pm

SALT LAKE CITY – The case against a former Salt Lake City IT employee accused of leaking undercover police information has raised questions and concerns about how the city and its police department safeguard sensitive information.

Officials have been tight-lipped about the incident and have refused multiple interview requests since the employee’s arrest last October, citing the pending investigation and criminal case. Now, documents obtained by the KSL Investigators reveal new information that led a judge to dismiss a felony charge in the criminal case as well as the costs to taxpayers adding up in the wake of what the city calls a security breach.

Case background

Patrick Driscoll, 50, is accused of providing identifying and compromising information about undercover Salt Lake City police officers to a man accused of running a sex-trafficking ring, in exchange for money or sex.

Patrick Driscoll

Since his October arrest, Driscoll faces additional charges suggesting he participated in and benefited from the alleged criminal enterprise.

During a hearing in March, Third District Judge Chelsea Koch ruled prosecutors presented enough evidence to bind over eight of the nine charges against Driscoll for trial.

The charges include aggravated human trafficking, obstruction of justice, computer crimes, aggravated exploitation of prostitution and a pattern of unlawful activity.

‘He did so with authorization’

Koch found insufficient evidence to bind over one felony charge of computer crimes interfering with critical infrastructure.

The charge relied on a sworn statement from the city detailing efforts to assess what happened.

“The Salt Lake City individual who has been tasked with going through has indicated that there were no security breaches,” Koch said. “If there were no security breaches, then the inference the court can draw is that he did so with authorization.”

That document, obtained by the KSL Investigators through a public records request, states more than 150 databases and all public safety software systems were reviewed for potential compromises but, “none have been found.”

Salt Lake City sworn statement by LarryDCurtis

Driscoll was never an officer or an employee of the police department but still had “full access to the police department as well as all city and law enforcement databases,” according to court documents.

Koch did bind over a second computer crimes count, however, citing supporting evidence that Driscoll took home files that should have been deleted and kept police images of prostitutes that he is accused of using for his own sexual gratification.

“The distinction I make there is that while he may have had initial authorization for that, he exceeded his authorization,” Koch said.

Breach or no breach?

No employee should have “carte blanche access to everything across an IT infrastructure,” according to Earl Foote, founder and CEO of Nexus IT.

Earl Foote

Foote is a cybersecurity expert who agreed to review the document obtained by the KSL Investigators. He said he believes a breach starts with intent, regardless of one’s level of authorization.

“If (information is) accessed, you know, in accordance with that person’s daily duties and roles to help support the organization and its users, fine. There’s no nefarious activity there,” Foote said. “Once it turns into, ‘I want access for a reason beyond that, that’s personal and or to expose it to third parties,’ yes, that constitutes a breach.”

Foote said it appears the city is taking appropriate steps to respond to the incident but noted most security breaches are preventable.

“I think there’s no question here that some of the common controls and measures that should happen within an IT department probably were not as robust as they should be,” he said.

Cost to taxpayers

The city’s sworn statement reveals another side of the fallout: the cost to taxpayers.

“Cyber incidents have become astronomically expensive,” said Foote, who told KSL the average cost of a security breach in Utah is $2.5 million.

While some of the information in the document is redacted, the statement notes a $12,000 expense as well as a $34,000 expense. The latter lines up with a $34,000 purchase order obtained by the KSL Investigators for a digital forensic audit procured by the city.

The statement also estimated 2,000 hours of employee time spent responding to the breach, totaling $90,000 using a conservative average hourly rate of $45. The total cost outlined in the document, as of Dec. 2, 2021, amounts to $136,000, which Foote anticipates will grow.

“I would easily suspect this one incident to escalate into the hundreds of thousands of dollars,” he said. “Maybe half a million plus, wouldn’t surprise me at all.”

A spokesperson in the mayor’s office confirmed the city does have a cybersecurity insurance policy that predates the breach, but it’s unclear how much, if any, of the costs will be covered. The city has not yet submitted a claim.


Have you experienced something you think just isn’t right? The KSL Investigators want to help. Submit your tip at investigates@ksl.com or 385-707-6153 so we can get working for you.

RELATED STORIES:

Trial ordered for man charged with using inside police info to aid prostitution ring
Former SLC IT employee now being charged with sex trafficking in addition to giving data to trafficker
Criminal case against ex-IT employee raises questions about SLC security measures
SLC IT employee arrested after allegedly providing undercover police data to human trafficker

KSL 5 TV Live

KSL Investigates

You’ve likely noticed a growing number of businesses that have gone completely cashless. When it ...

Matt Gephardt

Businesses are passing their credit card fees onto customers, what can you do?

You’ve likely noticed a growing number of businesses that have gone completely cashless. When it comes time to pay, it’ll involve a tap, swipe or maybe a click on an app. It's a phenomenon that is contributing to the price we pay for goods and services.

5 hours ago

Summer travel is about to take flight. That means a whole lot of points and miles being used and ea...

Matt Gephardt and Sloan Schrage

Thieves are going after your frequent flier mileage: how you can safeguard those miles and points

Summer travel is about to take flight. That means a whole lot of points and miles being used and earned, and cybercriminals know it.

1 day ago

Peggy Lundberg tells KSL’s Matt Gephardt about her experience of having her travel credit stolen....

Matt Gephardt and Sloan Schrage

Thieves stealing airline travel credits: How you can protect them

If someone steals your credit card or hacks into your bank account, federal law says you should get most of your money back. But what protections do you have when someone steals your airline travel credits?

2 days ago

Matt Gephardt looking over the CarShield documents for Scott Dumas....

Matt Gephardt and Sloan Schrage, KSL TV

West Haven man says extended auto warranty refuses to cover costly engine repair

Many drivers buy an extended auto warranty to help keep their car on the road, but when the extended warranty a West Haven man bought refused to cover replacing an engine, he decided to Get Gephardt.

6 days ago

Follow @KSL5TVLike us on Facebook...

Matt Gephardt

How hoarding documents puts you at risk for identity theft

Someone who knows what they’re doing can do a whole lot of damage with the scraps of paper you’ve stashed in filing cabinets, drawers and other various hiding places around your house.

7 days ago

IOC excludes Russian and Belarusian athletes from Paris 2024 Olympics opening ceremonies....

Matt Gephardt

Get Gephardt: How to stay ahead of the 2024 Olympics scams

As Utahns know firsthand from 2002, the Olympics can be a bit chaotic with millions in an unfamiliar place. The situation is sure to entice opportunistic con men with Olympic scams.

8 days ago

Sponsored Articles

Women hold card for scanning key card to access Photocopier Security system concept...

Les Olson

Why Printer Security Should Be Top of Mind for Your Business

Connected printers have vulnerable endpoints that are an easy target for cyber thieves. Protect your business with these tips.

Modern chandelier hanging from a white slanted ceiling with windows in the backgruond...

Lighting Design

Light Up Your Home With These Top Lighting Trends for 2024

Check out the latest lighting design trends for 2024 and tips on how you can incorporate them into your home.

Technician woman fixing hardware of desktop computer. Close up....

PC Laptops

Tips for Hassle-Free Computer Repairs

Experiencing a glitch in your computer can be frustrating, but with these tips you can have your computer repaired without the stress.

Close up of finger on keyboard button with number 11 logo...

PC Laptops

7 Reasons Why You Should Upgrade Your Laptop to Windows 11

Explore the benefits of upgrading to Windows 11 for a smoother, more secure, and feature-packed computing experience.

Stylish room interior with beautiful Christmas tree and decorative fireplace...

Lighting Design

Create a Festive Home with Our Easy-to-Follow Holiday Prep Guide

Get ready for festive celebrations! Discover expert tips to prepare your home for the holidays, creating a warm and welcoming atmosphere for unforgettable moments.

Battery low message on mobile device screen. Internet and technology concept...

PC Laptops

9 Tips to Get More Power Out of Your Laptop Battery

Get more power out of your laptop battery and help it last longer by implementing some of these tips from our guide.

Documents reveal financial fallout of Salt Lake City IT security breach