DIXON – An Internet virus used to steal more than $30,000 from a fund that pays Dixon Rural Fire Protection District pensions was traced to a user in Massachusetts, police said Tuesday.
Additionally, police have subpoenaed information on six accounts in banks across the country into which the missing funds were funneled, to determine whether the user is linked to those accounts, Detective Sgt. Matt Richards said.
The information may be in hand by mid-July, he said.
On May 17, the fire department called city and state police after they were notified by Sauk Valley Bank that there had been several unauthorized transfers from the account used to pay pensions.
Police believe someone in the fire department accessed a site that had a virus attached to it. The virus infiltrates a network then accesses bank and other personal information, they said.
Police have not yet determined which site the virus was attached to, Richards said.
Bank officials have said the hacker used the log-in information of the department’s secretary, who is one of two people with access to the account.
The computer and the bank account have since been replaced, Fire Chief Norris Tucker said. The department also has upgraded its firewall, and monthly pension payments are being made via paper checks instead of direct deposit.
It’s not much, Tucker said, but it’s the best they can do.
When investigators know more about how the computer was hacked, the department will have a better idea of how to prevent it, he said. At that point, with better security, the department’s pension board will reconsider direct deposit.
Six people now are drawing from the $3 million pension fund, fire officials have said. The fund itself and other department accounts do not appear to be affected.
– Reporter Emily Coleman contributed to this story.