Cyber & AI intelligence
Wasteland.
Briefs indexed2959
Issues30
Published Mondays07:30 CT
▣ Breach CITY-OF-MCMINNVILL 2026-10-01

City of McMinnville: RansomHouse Leak Still Exposed on Dark Web

"Records stolen from the City of McMinnville, Oregon, are still freely available on a dark web leak site about two months after the RansomHouse ransomware group claimed the attack. The city has confirmed that an intruder…"

Records stolen from the City of McMinnville, Oregon, are still freely available on a dark web leak site about two months after the RansomHouse ransomware group claimed the attack. The city has confirmed that an intruder accessed and copied files between June 1 and July 18, 2026. Its formal notice to affected people, mailed September 29, says the exposed data may include names, driver's license numbers and Social Security numbers. Reporting by KOIN 6, FOX 12 (KPTV) and Yamhill County News suggests the leak goes much further, including police investigative files, personnel records and internal affairs material. A local cybersecurity specialist told KOIN the leak site had logged about 53,000 visits as of September 30. No source independently verified that count. All six sources for this brief are local or secondary press. None is a primary filing, so any figure not taken from the city's notice is attributed below.

What Happened

The city's notice, as reported by KPTV, sets out this timeline:

KPTV reports that, going by the city's own account, the September 29 notice came "more than a month past the deadline Oregon law sets." Asked why, City Manager Adam Garvin replied only that the city had no comment beyond the notice. The city has not said how many people are affected. Yamhill County News reported that the FBI declined to comment, and no source confirms which agencies, if any, are investigating.

FOX 12 visited the RansomHouse leak site itself and confirmed the McMinnville listing. Without opening any files, it saw file names consistent with police records, personnel files and internal investigations.

What Was Taken

What the city has disclosed and what others say they saw on the leak site are far apart.

What the city says: Exposure varies by person and may include name, driver's license number and/or Social Security number.

What third parties report: - Chuck Dornon, CEO of Alexonet and a McMinnville resident with no working relationship with the city, told KOIN and KPTV he found tax returns, passwords, banking and HR information, and confidential police records. He said the police material included witness interviews from people who did not want to be named. His written notes also mention medical information, confidential witness testimony and municipal court records. Those same notes say he could not determine how many people were affected or authenticate every file. His surname appears as both "Dornon" and "Dornan" across the KOIN and KPTV coverage. - Yamhill County News reviewed material linked to the release. It reports data from city desktops and email accounts, elected officials, executive sessions and McMinnville Police Department systems, with some police material covering criminal investigations that span multiple years. Its headline names personnel, investigation-victim and internal affairs files. - FOX 12 saw file titles consistent with police records, personnel files and internal investigations, which backs up the other two accounts.

No source gives a total record count or data volume. Dornon told KOIN that RansomHouse appears to have published the data openly instead of selling it, so anyone can download it.

Why It Matters

The Attack Technique

None of the sources disclose the initial access vector. The city has not said whether the intrusion started with phishing, stolen credentials, an exposed remote access service or an unpatched edge device. The following is known:

What Organizations Should Do

  1. Separate law enforcement data from general municipal IT. Police case files, witness records and internal affairs material should sit on their own network segment and identity tier, so that compromising city desktops or email does not give access to them.
  2. Reduce dwell time with egress monitoring. A six-week intrusion window means exfiltration went unnoticed. Alert on large or unusual outbound transfers, new cloud storage destinations and archiving tools such as rclone, WinRAR and 7-Zip running on file servers.
  3. Check leak sites as soon as you detect an intrusion. Track ransomware leak listings from the first day of detection. If your data appears, base your notification scope on what has actually been published, not only on the minimum the law requires.
  4. Plan notifications ahead and meet the deadline. Draft templates and set up call center and credit monitoring vendors before an incident. If the investigation will take longer than the statutory window, send an initial notice anyway and follow up with more detail later.
  5. Rotate every credential that may be in the leak. Dornon reports that passwords were in the dump. Reset all affected accounts, service accounts and shared credentials, and enforce phishing-resistant MFA on remote access and email.
  6. Look after non-financial victims. Contact witnesses, victims and employees named in police and HR records directly. Offer safety-focused help, not just credit monitoring.

Sources: McMinnville Data Breach: 53K Visits to Leaked Records | ‘A treasure trove of information:’ Cybersecurity specialist says se... | City of McMinnville Data on Dark Web Following Ransomware Attack -... | McMinnville missed a legal deadline to disclose its data breach. It... | McMinnville reaching out to people who had private details stolen i... | City makes statement about data breach, confirms investigation ...