City of Columbus, Ohio
bd_ab0fca3ff7bb9fa0 · schema v1 · pii pii-v1
Full breach record for City of Columbus, Ohio →The City of Columbus, Ohio, experienced a cybersecurity incident on July 18, 2024, where a foreign threat actor gained unauthorized access to IT infrastructure, attempted to deploy ransomware, and solicited a ransom. The breach exposed personal information including names, DOBs, addresses, bank account info, driver's licenses, and SSNs for up to 500,000 individuals. Data was posted on the dark web. The City engaged cybersecurity experts and law enforcement. Notifications were sent on October 7, 2024, offering 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 18, 2024
Begins
Jul 18, 2024
Discovered
Nov 1, 2024
Filed
vs. sector median
+4 wks slower
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Siterhysidabd_1840a5188defe0682024-07-31 · +93dVerified by operator
- Leak Siterhysidabd_c07df1e00674c1622024-07-18 · +106dVerified
Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_cd6c46bfac4a64292024-11-01Verified by operator
- Indiana State AGbd_311cc9cd07f61dfb2024-10-07 · +25dVerified
- Montana State AGbd_a6d1d5c3250831742024-09-05 · +57dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Sep 5 (MT), last Nov 1 (ME) — a 57-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.