Fargo Park District
bd_0c6fca6c05e1155b · schema v1 · pii pii-v1
Full breach record for Fargo Park District →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
Fargo Park District: The Fargo Park District suffered a security breach in October, which disrupted phones, emails, and internal systems, and an investigation is still underway to determine the extent of the incident. Residents were not notified until weeks later, and it remains unclear whether any data was exposed. The district is working with experts to understand the scope of the incident, and residents who interacted with the district in late October are advised to monitor their bank accounts and be cautious of unsolicited emails or calls. Linked ransomware group: interlock.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Oct 27, 2025
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteinterlockbd_aef5e47b0104c5f22025-12-05 · +40dVerified by operator
Regulatory filings (3) · sorted by filing gap
- Vermont State AGbd_0b9b714c45111ada2026-07-13 · +259dVerified by operator
- Massachusetts State AGbd_cb3b6b5ef51e81ac2026-07-13 · +259dVerified by operator
- Nebraska State AGbd_dc1a441b4158ced42026-07-13 · +259dVerified by operator
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Oct 27, last Jul 13 (NE) — a 259-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
interlock
According to ransomware.live, Interlock is a ransomware group first observed in September 2024 that targets critical infrastructure sectors including healthcare, government, education, and technology across North America and Europe using double-extortion, with 57+ claimed victims including a major US dialysis provider exposing over two million patient records.