Records stolen from the City of McMinnville, Oregon, are still freely available on a dark web leak site about two months after the RansomHouse ransomware group claimed the attack. The city has confirmed that an intruder accessed and copied files between June 1 and July 18, 2026. Its formal notice to affected people, mailed September 29, says the exposed data may include names, driver's license numbers and Social Security numbers. Reporting by KOIN 6, FOX 12 (KPTV) and Yamhill County News suggests the leak goes much further, including police investigative files, personnel records and internal affairs material. A local cybersecurity specialist told KOIN the leak site had logged about 53,000 visits as of September 30. No source independently verified that count. All six sources for this brief are local or secondary press. None is a primary filing, so any figure not taken from the city's notice is attributed below.
What Happened
The city's notice, as reported by KPTV, sets out this timeline:
- June 1 to July 18, 2026: An unauthorized party had access to the city's network and copied files.
- On or about July 15: City staff noticed "unusual activity" and brought in outside investigators.
- About August 3 to 10: Public ransomware trackers, as reviewed by Yamhill County News, show RansomHouse listing McMinnville around August 3 to 6. Sample files appeared around August 6, and a larger release was marked as disclosed around August 9 or 10.
- September 15: The News-Register reported a city statement confirming the breach and an ongoing investigation. KPTV describes this as the city's first public acknowledgement, which came in mid-September.
- September 22: The city says its investigation was "in-part complete."
- September 29: Formal notices went out to affected individuals.
KPTV reports that, going by the city's own account, the September 29 notice came "more than a month past the deadline Oregon law sets." Asked why, City Manager Adam Garvin replied only that the city had no comment beyond the notice. The city has not said how many people are affected. Yamhill County News reported that the FBI declined to comment, and no source confirms which agencies, if any, are investigating.
FOX 12 visited the RansomHouse leak site itself and confirmed the McMinnville listing. Without opening any files, it saw file names consistent with police records, personnel files and internal investigations.
What Was Taken
What the city has disclosed and what others say they saw on the leak site are far apart.
What the city says: Exposure varies by person and may include name, driver's license number and/or Social Security number.
What third parties report: - Chuck Dornon, CEO of Alexonet and a McMinnville resident with no working relationship with the city, told KOIN and KPTV he found tax returns, passwords, banking and HR information, and confidential police records. He said the police material included witness interviews from people who did not want to be named. His written notes also mention medical information, confidential witness testimony and municipal court records. Those same notes say he could not determine how many people were affected or authenticate every file. His surname appears as both "Dornon" and "Dornan" across the KOIN and KPTV coverage. - Yamhill County News reviewed material linked to the release. It reports data from city desktops and email accounts, elected officials, executive sessions and McMinnville Police Department systems, with some police material covering criminal investigations that span multiple years. Its headline names personnel, investigation-victim and internal affairs files. - FOX 12 saw file titles consistent with police records, personnel files and internal investigations, which backs up the other two accounts.
No source gives a total record count or data volume. Dornon told KOIN that RansomHouse appears to have published the data openly instead of selling it, so anyone can download it.
Why It Matters
- The exposure goes beyond identity data. Witness identities, investigation-victim files and internal affairs records carry risks that credit monitoring cannot address, including witness intimidation, harm to ongoing or past cases, and reputational damage to people who were never charged.
- The leak is still live and free. A data dump that anyone can reach in a few clicks lowers the bar for opportunistic fraud. Dornon specifically warned about payday loan, credit card and mortgage fraud. Reach may also be growing: Dornon put visits at about 53,000, though that number does not show how many people downloaded or misused the data.
- The narrow notice gives a false sense of scope. People whose information sits in police, court or HR files may not realise they are at risk if the notice lists only SSNs and license numbers.
- The notification timeline is a problem. About eleven weeks passed between detection and individual notice. The data was public for roughly seven of those weeks. KPTV says the delay appears to breach Oregon's statutory deadline, and the city has not explained it. This pattern of late notification while the leak is already public keeps recurring in municipal ransomware incidents.
The Attack Technique
None of the sources disclose the initial access vector. The city has not said whether the intrusion started with phishing, stolen credentials, an exposed remote access service or an unpatched edge device. The following is known:
- The intruder appears to have been inside for about six and a half weeks (June 1 to July 18), and detection came only near the end of that period (July 15).
- Data was stolen before or alongside any disruption, which matches RansomHouse's usual extortion-led approach.
- The reported breadth of the leak, covering desktops, email, elected officials' material and police department systems, points to broad lateral movement or access to shared file stores. This is an inference from the reporting. The city has not confirmed it.
What Organizations Should Do
- Separate law enforcement data from general municipal IT. Police case files, witness records and internal affairs material should sit on their own network segment and identity tier, so that compromising city desktops or email does not give access to them.
- Reduce dwell time with egress monitoring. A six-week intrusion window means exfiltration went unnoticed. Alert on large or unusual outbound transfers, new cloud storage destinations and archiving tools such as rclone, WinRAR and 7-Zip running on file servers.
- Check leak sites as soon as you detect an intrusion. Track ransomware leak listings from the first day of detection. If your data appears, base your notification scope on what has actually been published, not only on the minimum the law requires.
- Plan notifications ahead and meet the deadline. Draft templates and set up call center and credit monitoring vendors before an incident. If the investigation will take longer than the statutory window, send an initial notice anyway and follow up with more detail later.
- Rotate every credential that may be in the leak. Dornon reports that passwords were in the dump. Reset all affected accounts, service accounts and shared credentials, and enforce phishing-resistant MFA on remote access and email.
- Look after non-financial victims. Contact witnesses, victims and employees named in police and HR records directly. Offer safety-focused help, not just credit monitoring.
Sources: McMinnville Data Breach: 53K Visits to Leaked Records | ‘A treasure trove of information:’ Cybersecurity specialist says se... | City of McMinnville Data on Dark Web Following Ransomware Attack -... | McMinnville missed a legal deadline to disclose its data breach. It... | McMinnville reaching out to people who had private details stolen i... | City makes statement about data breach, confirms investigation ...