Pittsburgh/ Crime & Emergencies

Aliquippa and Duquesne Police Chiefs' Emails Hacked, Thousands Get Fake Messages

AI Assisted Icon
Published on September 30, 2026
Aliquippa and Duquesne Police Chiefs' Emails Hacked, Thousands Get Fake Messages300 Franklin Ave — Reported Site of Aliquippa Email Hack
Google Street View

Recipients of messages appearing to come from two Western Pennsylvania police chiefs were urged to avoid opening attachments or clicking links after officials said the chiefs' email accounts had been compromised. The messages asked people to review attached documents, and Duquesne Chief Tom Shaw's account received thousands of replies before the breach was recognized.

What Recipients Were Told

The Aliquippa Police Department reported that fraudulent emails from Chief John Lane's account asked recipients to review multiple attached documents and provide feedback, according to WTAE. The message read, “Please take a moment to review the attached when you can.” Aliquippa officials confirmed Lane's account had been hacked.

WTAE also reported that Duquesne Police Chief Tom Shaw received an identical fraudulent email. R. Scott Adams told the outlet Shaw learned of the message after his daughter asked why he had sent it. Shaw then reviewed the email, found it suspicious and contacted IT.

A Large Volume of Replies

Shaw's account had received thousands of responses by the time the suspicious message was identified, WTAE reported. The volume of replies showed how widely the email had circulated before it was flagged.

Aliquippa officials advised anyone who received the message not to reply, click links, open attachments or share personal or financial information, according to WTAE. They said residents did not need to contact the department directly because officials were aware of the incident and taking action on the compromised account.

Advice for People Who Received the Email

Point Park University computer science professor Jeffrey Seaman told WTAE that phishing was a likely explanation for the breach. He advised anyone who opened a link to shut down their device, disconnect it from the internet, change their password immediately and enable two-factor authentication on their accounts going forward.

The incident comes amid broader concerns about criminal use of compromised government email accounts. The FBI has reported an increase in criminal-forum postings involving cybercrime services that exploit hacked police and government accounts, according to KrebsOnSecurity. Investigator Matt Donahue told the outlet that phishing emails and credentials stolen through opportunistic malware infections remain common ways criminals gain access.

KrebsOnSecurity has also reported cases in which compromised government email addresses were used to submit fraudulent emergency data requests that could expose personal information. Kodex, a data-request platform, told the outlet that it processed 1,597 such requests over a recent 12-month period; 485 failed a second layer of verification. The company also said it suspended nearly 4,000 law enforcement users during that period.

Email fraud in national context

The FBI's 2024 Internet Crime Complaint Center report recorded 21,442 business email compromise complaints and close to $2.8 billion in reported losses, according to Nacha's summary of the report. The figures show the scale of reported email-based compromise nationally; officials have not publicly reported whether this local incident caused financial losses.

Officials have not publicly detailed who accessed the Aliquippa and Duquesne accounts or whether recipients lost money or data. Their public guidance has focused on caution while the investigation continues.