Skip to main content
Language Translation
  Close Menu
  • Cybersecurity - Blogs
  • Municipal Bond Market - Serving Communities, Protecting Public Funds and Financing Integrity

Municipal Bond Market - Serving Communities, Protecting Public Funds and Financing Integrity

cybersecurity
$URLMapContent.image.altTag

PERSPECTIVES FROM THE FIELD 

The strength of Indiana is that we bring together a variety of perspectives from the plethora of areas that touch the field of cyber, especially through the Indiana Executive Council on Cybersecurity (IECC). Hence the name "Perspectives From the Field Series" in which we invite experts to discuss the real and challenging issues we are facing in the field and the proposed solutions from the experts to better the lives and businesses of all Hoosiers. 

In the first of a three-part blog series, members of the Council’s Finance Committee share their knowledge and expertise about the impact that cybersecurity is having in the municipal bond markets and the steps that financial institutions, together with state and local government officials, are taking to protect the investments that impact our communities. 

Providing their perspective is the Indiana Treasurer of State Daniel Elliott and Jacob Blasdel, who serves as the Executive Director of the Indiana Bond Bank. 

By Daniel Elliott and Jacob Blasdel   

Municipal Bond Market Cyber Risks Impact Communities and Critical Infrastructure

When a county, city, town, school district, or other local governmental unit determines that it is necessary to issue bonds, the transaction typically involves significant public investment and long-term financial commitments. 

These financings are the primary mechanism through which many large-scale construction projects are financed, from water and wastewater infrastructure to new schools. While these projects often generate debate about their necessity, a separate concern has emerged: instances in which bond transactions have been impacted by fraud, including schemes where cybercriminals interfere with the issuance process, misdirect bond proceeds, or compromise communications between issuers and financing partners. 

One of the most significant cyber-related threats facing municipal issuers today is business email compromise (BEC), where attackers gain access to or convincingly spoof trusted email accounts involved in a bond transaction. These attacks are designed to redirect wire transfers or alter payment instructions at critical stages, such as closing.

Although it occurred outside of Indiana, a recent incident in White Lake Township, Michigan illustrates the real and growing risk to municipal issuers everywhere. In late 2024, during the closing of an approximately $29 million general obligation bond issuance, a cybercriminal compromised township email communications and impersonated a township official, providing fraudulent wire instructions to the underwriter. As a result, the bond proceeds were wired to an unauthorized account controlled by the attacker. The bonds were ultimately canceled, and while a substantial amount of the funds have since been recovered, the incident led to significant disruption and potential litigation.

This case illustrates that cyber threats in the municipal bond market are not theoretical. They can directly impact the successful execution of a financing and the safeguarding of public funds.

Incidents like this highlight that even well-structured bond transactions can be vulnerable without strict verification protocols and secure communication practices. Preventing these incidents requires coordinated controls among all financing participants. Municipal issuers should focus on controls specifically designed for bond transactions and the movement of large sums of public funds: 

  • Secure Fund Transfers: Establish strict controls requiring dual authorization and out-of-band verification (such as a known phone number) for any wire instructions or changes to payment details; no changes should be accepted via email alone without independent verification.
  • Use Encryption: Encrypt sensitive financial information sent to the "deal team" (attorneys, underwriters, advisors) and consider using secure document-sharing platforms rather than standard email attachments.
  • Train Staff: Train personnel to recognize phishing and social engineering attacks targeting financial transactions.
  • Validate Third Parties: Confirm that underwriters, bond counsel, municipal advisors, paying agents, trustees, and other transaction participants follow procedures for identity verification, secure transmission of payment instructions, and escalation of anomalies.
  • Plan for Incidents: Develop a formal cybersecurity incident response plan, especially to address potential ransomware attacks, including procedures to pause or verify transactions if suspicious activity is detected during closing.
  • Immediate Escalation and Reporting: If suspicious payment activity is detected, immediately notify the relevant financial institutions, legal counsel, law enforcement, and cyber-response personnel.
  • Review Policies: Regularly update and review IT policies to address evolving threats.
  • Use Official Channels: Utilize resources from Indiana Cybersecurity for best practices. 
  • Transaction Verification Protocols: Establish a standardized process for confirming all wire instructions at closing using pre-verified contact information for all deal participants.

To learn more about resources available to assist local governments, visit the websites of the Indiana Bond Bank or the Indiana Treasurer of State Daniel Elliott, whose office is responsible for investing and safeguarding state funds and supporting local governments.