A City Account May Have Sent a Dangerous Email. Who Warns the Other Recipients?

On Thursday, July 16, I received an email purportedly from Jennifer Kellar of the City of Salem, Oregon. Gmail isolated the message and warned me about it.  I did not learn of the email until several days later when I reviewed my Spam folder.

Email from City of Salem With Google Warnings

Jennifer is, or was, Parks and Recreation Division Manager for the City of Salem.  I do not recall having previous communication with her.

By coincidence, I had sent an email to the Public Works department on July 15th, a day before, inquiring whether Salem had defined truck routes.  So I was expecting a reply from the City of Salem.

I’ve found that organizations often prepare responses and then send you a link to download a document or PDF that constitutes a response, so sending a link for a download is not outside the realm of possibility.  Nonetheless, I heeded Google’s warning and did not click the link.  Instead, I sent a separate email to Jennifer:

Hi Jennifer,

I have an email purportedly from you that Google Mail has tagged as spam.

Did you send me an email last Thursday?
John

Jennifer’s auto-reply facility sent an acknowledgment stating she was out of the office until Wednesday, July 22nd.  Then on Monday, July 20th, Jennifer wrote:

Unfortunately this was scam. Please disregard.

I think that, in her mind, that was the end of the matter.

Here‘s the problem email.  The following material header fields indicate that the message passed the City domain’s email-authentication checks and was treated by Microsoft as internally authenticated:

From: Jennifer Kellar <JKellar@cityofsalem.net>
Return-Path: <JKellar@cityofsalem.net>
spf=pass
dkim=pass
dmarc=pass
X-MS-Exchange-CrossTenant-AuthAs: Internal

However, I perceived a greater problem which she probably did not appreciate.  The problem is that I received an apparently malicious or credential-phishing message that passed the City domain’s authentication checks and was marked by Microsoft as internally authenticated.  I suspect I might not have been the only person who was targeted.

So we have a possible situation where email apparently from a municipal email server has been sent out to an unknown list of people with all the appearances of legitimacy. I brought the message to the sender’s attention, and she reasonably answered my immediate question by telling me that it was a scam and should be disregarded. But that response did not address the broader significance of the event.  I want to be very clear, I’m not blaming her, she acted reasonably.

I therefore contacted the City Manager’s office with this email which should have created some alarm:

JLP Email To City Manager re: IT Department Concern

The City responded Tuesday, July 21st, 2026 at 10:02 AM, with:

Mr. Poole, thank you for reaching out to the City, we have forwarded this to our IT department and they will investigate.

I did not expect the person sending me this email to fully appreciate the point I was making, but I did expect to hear from the IT department, possibly asking of a copy of the email I had received or at least acknowledging that they are now aware of the problem.

Four hours later, I then sent another email underscoring my concern, this time copying the City Attorney’s office.  My terminology in this message was imprecise—I did not yet know whether the link delivered malware or attempted credential theft—but my concern was the possible existence of other recipients:

My concerns are two-fold:
1. there appears to have been a compromise of a city employee's account and/or machine, that's something your IT department will assess.
2. The more important issue is: when it is determined an email with vectors for virus has issued from the City's email server, what steps are taken to warn recipients of the breach?

If I were less careful, I might have trusted the email since the return address was your domain and clicked the link to a presumed virus vector. Google's security check is the only reason I hesitated so I took the extra step contact the sender only to learn of this breach.  I submit the City has a duty to reach out to every person who was sent such unauthorized email and alert them that 1) the email was not authorized, and 2) if they tried to open the document, their system may be compromised.  

To ignore possible damage the vector may present to less-savvy and trusting people is not sufficient.

Thank you for your further consideration.

John Poole

24 hours later, no response or acknowledgment.

So the above presents an interesting question:

When an organization learns that authentic-looking malicious email was sent through—or convincingly appeared to come through—its systems, what responsibility does it have to investigate and warn other possible recipients who may have acted upon the message?

I’ve written this to share on Mastodon and see what other people, especially in IT management and security think.  I do note that we’re dealing with a public agency and not a private person or company, and for that reason I think there is a higher level of duty present. I do not know what the City’s IT department has done internally, and it may be investigating without discussing the details. But when a recipient supplies evidence that an authenticated government account sent a dangerous message, should the organization at least preserve the message, determine its scope, and consider warning other recipients? What is accepted practice?

My purpose is not to assign blame, but to determine what responsible incident handling requires when a trusted public account may have been used to reach unknown recipients. I would particularly welcome the views of people who work in information security, municipal IT, incident response, public administration, or privacy law.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *