MalwareRansomwareData EncryptedData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
City of Suffolk Virginia
bd_658ce4bb4e6a0629 · schema v1 · pii pii-v1
Full breach record for City of Suffolk Virginia →The City of Suffolk, VA, notified the New Hampshire Attorney General of a ransomware incident discovered on February 25, 2026. Malicious actors accessed the network on February 24, 2026, attempting to encrypt data. 53 individuals were potentially affected, with exposure of names, SSNs, passport numbers, and financial account data. The City engaged forensic experts, notified the FBI, and terminated access. No evidence of misuse was found.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_2e5262f6c8a9b26bTexas State AGfiled 2026-04-22(2d gap)Candidate
- bd_9da122387e5abb26Indiana State AGfiled 2026-04-22(2d gap)Verified
- bd_c52256f6a07e9db5Maine State AGfiled 2026-05-26(36d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/city-suffolk-va-20260420.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 20, 2026
- Raw hash
- 67c48a90d1899a763ea8f7f01f6a12fef5ec8e79a78b7f0384d1bf32f6128709
Reporting entity
- Name
- City of Suffolk Virginianorm: city of suffolk virginia
Victim entity
- Name
- City of Suffolk Virginianorm: city of suffolk virginia
Incident
- Discovered
- Feb 25, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 53
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Officereported the attack to the Federal Bureau of Investigation (FBI) Cyber Division and the Virginia Fusion Center
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.