MalwareRansomwarePhishingData ExfiltratedData EncryptedData PublishedRansom DemandedMulti-Stage ChainCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
City of La Vergne
bd_ce3cdb0643361e3c · schema v1 · pii pii-v1
Full breach record for City of La Vergne →City of La Vergne, Tennessee, notified Massachusetts residents of a ransomware attack discovered on October 17, 2025. Criminal actors encrypted the City's network, accessed PII (names, SSNs, driver's license numbers), and published stolen data online. The City engaged the FBI and TBI, isolated the network, and retained forensic vendors. Remediation includes migrating to cloud environments, rebuilding networks, and offering IDX identity protection services to affected individuals.
Massachusetts clock✗ MA AG >90d32 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by dragonforce about this victim predates this filing by 227 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_27c878ffbf3c43a0Vermont State AGfiled 2026-06-23(22d gap)Verified
- bd_cbeb9c854cbd4102Indiana State AGfiled 2026-06-26(25d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-1039-city-of-la-vergne-tennessee/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- 5bcc772edd40129891f162cc4eb3ce7518c6607e2c0fdc1ddb18719cd8040ce5
Reporting entity
- Name
- City of La Vergnenorm: city of la vergne
- Domain
- lavergnetn.gov
Victim entity
- Name
- City of La Vergnenorm: city of la vergne
- Domain
- lavergnetn.gov
Incident
- Discovered
- Oct 17, 2025
- Materiality determined
- —
- Notification sent
- Jun 26, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 ChannelT1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Contacted the T.B.I. and the F.B.I., who have been on-site assisting with the investigation
- Initial access
- phishing_link
Compliance
- Time to disclose
- 32 weeks(227 days from discovery to filing)
- Compliance flags
- MA AG >90dLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.