City of Dallas, Texas
bd_693af8d46a6ecaaa · schema v1 · pii pii-v1
Full breach record for City of Dallas, Texas →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group BlackSuit (formerly Royal) on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
“There is still no indication that data from residents, vendors or employees has been leaked,” Dallas said Monday in a statement. So, we are going to indicate that the data will be leaked soon. We will share here in our blog tons of personal information of employees (phones, addresses, credit cards, SSNs, passports), detailed court cases, prisoners, medical information, clients' information and thousands and thousands of governmental documents.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
May 19, 2023
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- HHS OCRbd_4757b937287a5f022023-08-03 · +76dVerified by operator
Filing propagation · 2 filings
View merged incident ↗Pattern: first filing May 19, last Aug 3 (TX) — a 76-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
blacksuit
According to ransomware.live, According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware.