We don't know whether the most recent response to this request contains information or not – if you are Michael Curry please sign in and let everyone know.

Sussex County Cybersecurity Incident and Reporting Compliance (October 31, 2025)

Michael Curry made this OPRA request to Sussex County Automatic anti-spam measures are in place for this older request. Please let us know if a further response is expected or if you are having trouble responding.

We're waiting for Michael Curry to read a recent response and update the status.

Dear Sussex County,

Please accept this electronic request for public records made under OPRA and the common law right of access. I am not required to fill out an official form or use a particular software platform to submit my request per N.J.S.A. 47:1A-6(f), which states that an email from a requestor including all of the information required on the adopted form shall suffice in place of a completed form as a valid government record request.

I HAVE NOT been convicted of any indictable offense under the laws of New Jersey, any other state, or the United States.
I WILL NOT use the requested government records for a commercial purpose.
I AM NOT seeking records in connection with a legal proceeding.

Records requested:

Please provide copies of all records, reports, correspondence, or electronic communications created, received, or maintained by Sussex County Government concerning the October 31, 2025 cybersecurity incident involving the sussex.nj.us email domain, in which County IT staff publicly acknowledged that “a couple of compromised email accounts were sending this message out.”

Specifically, I request: Incident Discovery and Containment: Help-desk logs, internal messages, or incident tickets documenting the first discovery of unauthorized access, phishing, or spoofing activity within County email or Microsoft 365/Mimecast systems between October 30 and November 4, 2025.

The original County-wide “Phishing Alert” email or memo issued on October 31, 2025, and any drafts, follow-ups, or communications related to its release.

The names and titles of County employees or consultants tasked with investigating or mitigating the incident.

Statutory Reporting under N.J.S.A. 56:8-163: Any reports, emails, or correspondence sent to or received from the New Jersey Cybersecurity & Communications Integration Cell (NJCCIC), New Jersey State Police Cyber Crimes Unit, or Office of Homeland Security & Preparedness regarding this incident.

Any confirmation, case number, or acknowledgment from those agencies evidencing the County’s compliance—or failure to comply—with the 72-hour reporting requirement in N.J.S.A. 56:8-163(a).

Any internal discussions, memoranda, or decisions analyzing whether Sussex County was obligated to report the incident and what actions were taken.

Administrative and Inter-Departmental Communications: Emails or memoranda exchanged among the County Administrator’s Office, IT Department, and Board of County Commissioners concerning discovery of the breach, possible data exposure, or decisions about notification to residents or State agencies.

Preservation and Forensic Records: Microsoft 365 audit logs, Mimecast delivery logs, or other forensic summaries from October 29 – November 4, 2025.

Any directive, instruction, or communication ordering preservation or retention of digital evidence or audit trails relating to the incident.

Meetings and Board Materials: Agendas, minutes, or executive-session certifications for any Board of County Commissioners meetings held between October 31 and November 12, 2025, where cybersecurity, NJCCIC, or the October 31 incident was discussed. Or if this will be placed on the November 12 Agenda as an item.

Any records showing whether such discussions were publicly noticed in compliance with the Open Public Meetings Act (N.J.S.A. 10:4-6 et seq.).

Public Statements and Media Correspondence: Drafts, talking points, or final versions of any press statements or public notices prepared or issued regarding this incident. Specifically to alert County residents of a password / data breach.

Any correspondence with journalists or members of the media concerning the breach or subsequent investigation including Straus News.

Identification of Impacted Accounts and Data Exposure: Records identifying which County email addresses, departments, or user accounts were confirmed or suspected to have been compromised in the October 31, 2025 incident.

Any lists, spreadsheets, or internal memoranda summarizing impacted users, mailboxes, or systems, including whether external recipients or members of the public were affected.

Copies of any notifications sent to affected employees, officials, vendors, or residents advising them of possible data exposure, credential compromise, or password resets.

Any internal communications discussing whether personally identifiable information (PII), government correspondence, or confidential materials were accessed, exfiltrated, or transmitted outside County control.

Any communications with Microsoft, Mimecast, or other service providers relating to compromised accounts, forensic analysis, or mitigation steps.

Incident Response and Remediation: Copies of any after-action report, internal summary, or post-incident review prepared by the County IT Department or any outside consultant.

All records showing the timeline of response measures, including password resets, access lockdowns, notifications to staff, and restoration of affected systems.

Any correspondence with cybersecurity vendors, consultants, or insurers engaged to handle response or remediation.

Any records of County-wide policy revisions or new directives issued following the incident (for example, new phishing-training requirements, MFA enforcement, or incident-response protocols).

My preferred delivery method for response(s) to this request is by e-mail as attachments.
Please confirm you have received this request. If you are not the custodian of records, please forward my request to that person and provide their email address to me for future reference.

Yours faithfully,
Michael Curry.

Serena DiMaso, Sussex County

1 Attachment

Good morning,

 

Please accept this email on behalf of Sussex County.

 

The County is in receipt of your OPRA request for the following:

 

1. Please provide copies of all records, reports, correspondence, or
electronic communications created, received, or maintained by Sussex
County Government concerning the October 31, 2025 cybersecurity incident
involving the [1]sussex.nj.us email domain, in which County IT staff
publicly acknowledged that “a couple of compromised email accounts were
sending this message out.”

 

2. Specifically, I request: Incident Discovery and Containment: Help-desk
logs, internal messages, or incident tickets documenting the first
discovery of unauthorized access, phishing, or spoofing activity within
County email or Microsoft 365/Mimecast systems between October 30 and
November 4, 2025.

 

3. The original County-wide “Phishing Alert” email or memo issued on
October 31, 2025, and any drafts, follow-ups, or communications related to
its release.

 

4. The names and titles of County employees or consultants tasked with
investigating or mitigating the incident.

 

5. Statutory Reporting under N.J.S.A. 56:8-163: Any reports, emails, or
correspondence sent to or received from the New Jersey Cybersecurity &
Communications Integration Cell (NJCCIC), New Jersey State Police Cyber
Crimes Unit, or Office of Homeland Security & Preparedness regarding this
incident.

 

6. Any confirmation, case number, or acknowledgment from those agencies
evidencing the County’s compliance—or failure to comply—with the 72-hour
reporting requirement in N.J.S.A. 56:8-163(a).

 

7. Any internal discussions, memoranda, or decisions analyzing whether
Sussex County was obligated to report the incident and what actions were
taken.

 

8. Administrative and Inter-Departmental Communications: Emails or
memoranda exchanged among the County Administrator’s Office, IT
Department, and Board of County Commissioners concerning discovery of the
breach, possible data exposure, or decisions about notification to
residents or State agencies.

 

9. Preservation and Forensic Records: Microsoft 365 audit logs, Mimecast
delivery logs, or other forensic summaries from October 29 – November 4,
2025.

 

10. Any directive, instruction, or communication ordering preservation or
retention of digital evidence or audit trails relating to the incident.

 

11. Meetings and Board Materials: Agendas, minutes, or executive-session
certifications for any Board of County Commissioners meetings held between
October 31 and November 12, 2025, where cybersecurity, NJCCIC, or the
October 31 incident was discussed. Or if this will be placed on the
November 12 Agenda as an item.

 

12. Any records showing whether such discussions were publicly noticed in
compliance with the Open Public Meetings Act (N.J.S.A. 10:4-6 et seq.).

 

13. Public Statements and Media Correspondence: Drafts, talking points, or
final versions of any press statements or public notices prepared or
issued regarding this incident. Specifically to alert County residents of
a password / data breach.

 

14. Any correspondence with journalists or members of the media concerning
the breach or subsequent investigation including Straus News.

 

15. Identification of Impacted Accounts and Data Exposure: Records
identifying which County email addresses, departments, or user accounts
were confirmed or suspected to have been compromised in the October 31,
2025 incident.

 

16. Any lists, spreadsheets, or internal memoranda summarizing impacted
users, mailboxes, or systems, including whether external recipients or
members of the public were affected.

 

17. Copies of any notifications sent to affected employees, officials,
vendors, or residents advising them of possible data exposure, credential
compromise, or password resets.

 

18. Any internal communications discussing whether personally identifiable
information (PII), government correspondence, or confidential materials
were accessed, exfiltrated, or transmitted outside County control.

 

19. Any communications with Microsoft, Mimecast, or other service
providers relating to compromised accounts, forensic analysis, or
mitigation steps.

 

20. Incident Response and Remediation: Copies of any after-action report,
internal summary, or post-incident review prepared by the County IT
Department or any outside consultant.

 

21. All records showing the timeline of response measures, including
password resets, access lockdowns, notifications to staff, and restoration
of affected systems.

 

22. Any correspondence with cybersecurity vendors, consultants, or
insurers engaged to handle response or remediation.

 

23. Any records of County-wide policy revisions or new directives issued
following the incident (for example, new phishing-training requirements,
MFA enforcement, or incident-response protocols).

 

Your request is denied in the whole. Specifically as to items 1, 7, 10,
12-14, 17, 21 and 23 are denied as too broad. Also items 4 and 6 are
requests for information not a government document. Please see; Bent v.
Stafford Police Dep’t, 381 N.J. Super. 30 (App. Div. 2005): The Court
affirmed the GRC’s decision (GRC Complaint No. 2004-78) that the
complainant’s request was broad and unclear (“any and all”). The Council
ruled that the information sought did not amount to an identifiable
government record. And  MAG Entm’t, LLC v. Div. of Alcohol Beverage
Control, 375 N.J. Super. 534 (App. Div. 2005): The Court held that
“[w]hile OPRA provides an alternative means of access to government
documents not otherwise exempted from its reach, it is not intended as a
research tool litigants may use to force government officials to identify
and siphon useful information. Rather, OPRA simply operates to make
identifiable government records ‘readily accessible for inspection,
copying, or examination.’ N.J.S.A. 47:1A-1.” (emphasis added). The Court
further held that “[u]nder OPRA, agencies are required to disclose only
‘identifiable’ government records not otherwise exempt . . . In short,
OPRA does not countenance open-ended searches of an agency's files.” Id.
at 549 (emphasis added).

As to items, 1, 2, 8, 7-10, and 15-23 they are denied under the security
exemption specifically allowed under the statute. Administrative or
technical information regarding computer hardware, software and networks
which, if disclosed would jeopardize computer security. N.J.S.A. 47:1A-1.1
(10)

As to items 3 and 14 they are denied as to form.  Please see. Elcavage v.
West Milford Twp. (Passaic), GRC Complaint No. 2009-07 (April 2010): The
Council held that “an OPRA request for an e-mail or e-mails shall
therefore focus upon the following four (4) characteristics: • Content
and/or subject • Specific date or range of dates • Sender • Recipient.

Item 11 is denied as these minutes need to be formally adopted and are not
yet available, however you can find all adopted meeting minutes are
available at [2]Meeting Schedules - Sussex County

 

Also as of September 3, 2024, the OPRA laws were amended. The new
amendments prohibit a party to a legal proceeding from filing an OPRA
request, if the records sought are the subject of a court order or pending
discovery request. It is our good faith belief that this request is in
fact being made by a party to a current legal proceeding. Therefore, each
of the aforementioned requests, in addition to any and every other request
not otherwise specifically reflected herein, is denied under N.J.S.A.
47:1A-1.1

 

Thank you,

 

 

Serena DiMaso, Esq

 

Florio, Perrucci, Steinhardt, Cappelli & Tipton LLC

91 Larry Holmes Dr.

Easton, PA 18042

 

Cell: 848.893.6669

 

[3][email address] / [4]www.floriolaw.com

Licensed in NYS

 

 

 

 

STATEMENT OF CONFIDENTIALITY: The information contained in this
transmission including any attached documentation is privileged and
confidential. It is intended only for the use of the individual or entity
named above. If the reader of this message is not the intended recipient,
you are hereby notified that any dissemination, distribution or copy of
this communication is strictly prohibited. If you have received this
communication in error, please notify Florio Perrucci Steinhardt Cappelli
& Tipton LLC immediately by replying to this e-mail. Please delete all
copies of this message and any attachments immediately.

 

From: Michael Curry <[OPRA #83102 email]>
Sent: Thursday, November 6, 2025 9:09 AM
To: Serena DiMaso <[Sussex County request email]>
Subject: OPRA request - Sussex County Cybersecurity Incident and Reporting
Compliance (October 31, 2025)

 

 

Dear Sussex County,

 

Please accept this electronic request for public records made under OPRA
and the common law right of access. I am not required to fill out an
official form or use a particular software platform to submit my request
per N.J.S.A. 47:1A-6(f), which states that an email from a requestor
including all of the information required on the adopted form shall
suffice in place of a completed form as a valid government record request.

 

I HAVE NOT been convicted of any indictable offense under the laws of New
Jersey, any other state, or the United States.

I WILL NOT use the requested government records for a commercial purpose.

I AM NOT seeking records in connection with a legal proceeding.

 

Records requested:

 

Please provide copies of all records, reports, correspondence, or
electronic communications created, received, or maintained by Sussex
County Government concerning the October 31, 2025 cybersecurity incident
involving the [5]sussex.nj.us email domain, in which County IT staff
publicly acknowledged that “a couple of compromised email accounts were
sending this message out.”

 

Specifically, I request: Incident Discovery and Containment: Help-desk
logs, internal messages, or incident tickets documenting the first
discovery of unauthorized access, phishing, or spoofing activity within
County email or Microsoft 365/Mimecast systems between October 30 and
November 4, 2025.

 

The original County-wide “Phishing Alert” email or memo issued on October
31, 2025, and any drafts, follow-ups, or communications related to its
release.

 

The names and titles of County employees or consultants tasked with
investigating or mitigating the incident.

 

Statutory Reporting under N.J.S.A. 56:8-163: Any reports, emails, or
correspondence sent to or received from the New Jersey Cybersecurity &
Communications Integration Cell (NJCCIC), New Jersey State Police Cyber
Crimes Unit, or Office of Homeland Security & Preparedness regarding this
incident.

 

Any confirmation, case number, or acknowledgment from those agencies
evidencing the County’s compliance—or failure to comply—with the 72-hour
reporting requirement in N.J.S.A. 56:8-163(a).

 

Any internal discussions, memoranda, or decisions analyzing whether Sussex
County was obligated to report the incident and what actions were taken.

 

Administrative and Inter-Departmental Communications: Emails or memoranda
exchanged among the County Administrator’s Office, IT Department, and
Board of County Commissioners concerning discovery of the breach, possible
data exposure, or decisions about notification to residents or State
agencies.

 

Preservation and Forensic Records: Microsoft 365 audit logs, Mimecast
delivery logs, or other forensic summaries from October 29 – November 4,
2025.

 

Any directive, instruction, or communication ordering preservation or
retention of digital evidence or audit trails relating to the incident.

 

Meetings and Board Materials: Agendas, minutes, or executive-session
certifications for any Board of County Commissioners meetings held between
October 31 and November 12, 2025, where cybersecurity, NJCCIC, or the
October 31 incident was discussed. Or if this will be placed on the
November 12 Agenda as an item.

 

Any records showing whether such discussions were publicly noticed in
compliance with the Open Public Meetings Act (N.J.S.A. 10:4-6 et seq.).

 

Public Statements and Media Correspondence: Drafts, talking points, or
final versions of any press statements or public notices prepared or
issued regarding this incident. Specifically to alert County residents of
a password / data breach.

 

Any correspondence with journalists or members of the media concerning the
breach or subsequent investigation including Straus News.

 

Identification of Impacted Accounts and Data Exposure: Records identifying
which County email addresses, departments, or user accounts were confirmed
or suspected to have been compromised in the October 31, 2025 incident.

 

Any lists, spreadsheets, or internal memoranda summarizing impacted users,
mailboxes, or systems, including whether external recipients or members of
the public were affected.

 

Copies of any notifications sent to affected employees, officials,
vendors, or residents advising them of possible data exposure, credential
compromise, or password resets.

 

Any internal communications discussing whether personally identifiable
information (PII), government correspondence, or confidential materials
were accessed, exfiltrated, or transmitted outside County control.

 

Any communications with Microsoft, Mimecast, or other service providers
relating to compromised accounts, forensic analysis, or mitigation steps.

 

Incident Response and Remediation: Copies of any after-action report,
internal summary, or post-incident review prepared by the County IT
Department or any outside consultant.

 

All records showing the timeline of response measures, including password
resets, access lockdowns, notifications to staff, and restoration of
affected systems.

 

Any correspondence with cybersecurity vendors, consultants, or insurers
engaged to handle response or remediation.

 

Any records of County-wide policy revisions or new directives issued
following the incident (for example, new phishing-training requirements,
MFA enforcement, or incident-response protocols).

 

My preferred delivery method for response(s) to this request is by e-mail
as attachments.

Please confirm you have received this request. If you are not the
custodian of records, please forward my request to that person and provide
their email address to me for future reference.

 

Yours faithfully,

Michael Curry.

 

-------------------------------------------------------------------

 

Please deliver records electronically via email to the below UNIQUE
address for all replies to this request:

[6][OPRA #83102 email]

 

Is [7][Sussex County request email] the wrong address for OPRA requests to Sussex
County? If so, please contact us using this form:

[8]https://opramachine.com/change_request/n...

Disclaimer: This message and any reply that you make will be published on
the internet. Our privacy and copyright policies:

[9]https://opramachine.com/help/officers

 

View this OPRA request & responses online:

[10]https://opramachine.com/request/sussex_c...

 

 

Please note that in some cases publication of requests and responses will
be delayed.

 

If you find this service useful as an OPRA custodian, please ask your web
manager to link to us from your organisation's website.

 

"OPRAmachine’s mission is to give people easy and affordable access to New
Jersey public records.

For more information, contact us at: ‪(732) 707-1628 or PO Box 3180, New
Brunswick, NJ 08903."

 

show quoted sections

We don't know whether the most recent response to this request contains information or not – if you are Michael Curry please sign in and let everyone know.