MalwareRansomwareStolen CredentialsData ExfiltratedData PublishedRansom DemandedCustomer Data InvolvedEmployee Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICLowActive
City Of Columbus
bd_c3229be5e89157e6 · schema v1 · pii pii-v1
Full breach record for City Of Columbus →The City of Columbus, OH, reported a cybersecurity incident discovered on July 18, 2024, involving a foreign threat actor attempting to deploy ransomware and solicit payment. The actor gained unauthorized access to IT infrastructure, potentially exposing PII of residents, employees, and visitors. Data was posted on the dark web. 19 New Hampshire residents were identified as affected. The City engaged legal counsel, forensic experts, and law enforcement, and offered credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed19 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/city-columbus-oh-20241101.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 1, 2024
- Raw hash
- 352b6a963a1e35bf49ab246dab69c668956f40c1c73f2756e06787123137abc7
Reporting entity
- Name
- City Of Columbusnorm: city of columbus
- Domain
- cityofcolumbus.org
Victim entity
- Name
- City Of Columbusnorm: city of columbus
- Domain
- cityofcolumbus.org
Incident
- Discovered
- Jul 18, 2024
- Materiality determined
- —
- Notification sent
- Oct 7, 2024
- Affected individuals
- 19
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 weeks(106 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.