SYS::ONLINE
Wasteland.
Briefs1781
Issues22
SinceFeb 2026
LIVE
█ Ransomware CITY-OF-MCMINNVILL 2026-08-08

City of McMinnville, Oregon: RansomHouse Extortion Claim

"On August 6, 2026, the RansomHouse extortion group added the City of McMinnville, Oregon (mcminnvilleoregon.gov) to its dark web victim list, threatening to publish stolen municipal data unless city representatives open…"

On August 6, 2026, the RansomHouse extortion group added the City of McMinnville, Oregon (mcminnvilleoregon.gov) to its dark web victim list, threatening to publish stolen municipal data unless city representatives open negotiations. Two threat-intelligence trackers, DeXpose and UNDERCODE NEWS (the latter citing monitoring by the ThreatMon Threat Intelligence Team), reported the listing on the same day. Both are OTHER-tier sources observing the same leak-site post, and neither reports independent verification. As of this writing the city has issued no public statement, no regulator filing has surfaced, and no established security outlet has confirmed the intrusion. What is documented is the extortion claim, not yet its substance.

What Happened

The available reporting is consistent and thin. DeXpose logs the target as "City of McMinnville OR," domain mcminnvilleoregon.gov, country USA, attacking group RansomHouse, date reported August 6, 2026. It quotes the actor's posted message verbatim: "The full leak will be published soon, unless a company representative contacts us via the channels provided." UNDERCODE NEWS describes the same event as a victim-list addition detected through dark web ransomware monitoring channels on August 6, 2026.

That phrasing matters. A leak-site listing with a contact-us ultimatum and no published sample is the opening move of a double-extortion negotiation, not proof of a completed data dump. Neither source states an encryption event, a service outage, a volume of stolen data, or a ransom amount. Neither reports contacting the city for comment.

Readers should treat the current state of knowledge as: RansomHouse asserts it holds McMinnville data; that assertion is unverified. Leak-site claims are frequently accurate and occasionally inflated, recycled, or attributed to a third-party vendor rather than the named organization. The Comparitech reporting on a comparable municipal case is instructive on how long the gap between claim and confirmation can run: SafePay claimed Middletown, Ohio on September 12, 2025, and Comparitech notes the city never acknowledged that claim, while the formal victim notification did not go out until 2026. Comparitech's own tally of SafePay puts 505 claimed attacks against only 76 publicly confirmed by the targeted organizations, a reminder that leak-site postings and confirmed breaches are different populations.

What Was Taken

Nothing specific is known. No source reports a record count, a data category, a file listing, or a sample release for McMinnville. Any figure circulating at this stage would be invented.

What can be said is what a city of McMinnville's profile plausibly holds, and what comparable municipal breaches have actually exposed once investigations concluded:

The pattern across all three: Social Security numbers, payroll and tax records, health data from employee benefits or municipal health programs, and resident service files. If RansomHouse's claim holds, that is the category of material at risk in McMinnville. It is not confirmation that any of it was taken.

Why It Matters

McMinnville is a small operation. LinkedIn profile data for a long-serving city Information Systems Specialist characterizes the City of McMinnville as a government agency of roughly 30 to 40 employees, founded in 1856. Whatever the precise headcount, this is not an organization with a staffed 24/7 SOC. UNDERCODE NEWS makes the structural point directly: local governments are attractive because they hold valuable data and run essential services while facing resource constraints large enterprises do not.

The strategic context is worse than any single listing suggests. Tenable's Research Special Operations team, tracking a coordinated campaign against U.S. water and wastewater systems, reports disruption across at least 12 states including more than 30 Minnesota communities, with the FBI identifying targeted PLC models and reported operational impacts including pressure loss and flooding. Tenable notes attribution remains pending federal investigation, though the timing aligns with escalating Iranian-affiliated PLC exploitation activity documented by CISA. That is a distinct campaign with a different actor profile and no connection to RansomHouse or to McMinnville. It matters here because it establishes the load: small U.S. municipalities are absorbing simultaneous pressure from financially motivated extortion crews and from state-aligned operators probing exposed operational technology, with the same thin IT teams answering both.

The Middletown case shows the tail cost. Comparitech reports the attack disrupted city services including water utility billing, which was not fully restored until January 2026, months after the July 2025 breach. Forensic review and document analysis ran until May 18, 2026. For a city government, the incident is not the week of the ransom note. It is the year that follows.

The Attack Technique

Unknown. No source identifies an initial access vector, a vulnerability, a phishing lure, or a compromised credential for McMinnville. No indicators of compromise have been published. The only technical fact on record is the extortion methodology: dark web victim listing plus a deadline plus a contact channel, which UNDERCODE NEWS describes as combining technical intrusion, data theft, public pressure, and dark web exposure to maximize leverage.

Comparable municipal intrusions offer little more. Comparitech states plainly it does not know how attackers breached Middletown's network, whether a ransom was paid, or what was demanded. New Britain has not disclosed how its breach occurred. Saint Paul's investigation was ongoing as of July 2026. The recurring shape of these cases is a multi-week dwell period before detection: in the Middletown incident, files were removed between July 29 and August 17, 2025, and the city learned of the incident on August 17, 2025. In an unrelated healthcare case reported by HIPAA Journal, Minnesota Epilepsy Group found unauthorized access spanning March 16 to April 10, 2026 after spotting suspicious activity on April 7. Exfiltration windows measured in weeks, discovery at the tail end.

DeXpose's guidance, which is vendor-marketing framing around standard advice, recommends assuming persistence mechanisms may remain active and scoping the full intrusion rather than the visible symptom. That instinct is correct regardless of who is selling it.

What Organizations Should Do

For McMinnville peers, small and mid-sized municipal governments running lean IT with broad data holdings:

  1. Treat a leak-site listing as an incident trigger, not a PR problem. If your organization appears on an extortion site, launch a full compromise assessment immediately: determine the entry point, what was exfiltrated, and whether persistence remains. Engage incident response counsel and forensic specialists before any contact with the actor, as DeXpose recommends and as standard IR practice requires.
  2. Make backups immutable and offline. Ransomware crews target backup infrastructure first. Verify restoration by actually restoring, not by confirming a job completed. Middletown's water billing took roughly five months to fully restore; that is a recovery-capability failure as much as a security one.
  3. Enforce phishing-resistant MFA everywhere, including VPN, remote admin, and vendor accounts. Credential reuse harvested by infostealers remains a dominant municipal entry path. Monitor for exposed credentials tied to your domains.
  4. Segment operational technology from business IT. Tenable's water-sector reporting and the FBI's identification of targeted PLC models make the case: internet-exposed controllers and flat networks convert a business-side compromise into a public-safety event. Inventory every internet-facing device and pull unnecessary exposure off the public internet.
  5. Pre-write the notification and regulator workflow. The New Britain filing shows how a Vermont-only figure becomes the entire public record when a city has not scoped the nationwide impact. Know in advance which state AGs you must notify, on what clock, and who signs off.
  6. Retain and centralize logs for at least 12 months. Every case above turned on reconstructing a weeks-long access window months after the fact. Without retained telemetry, the honest answer to "what was taken" is permanently "we cannot say."

For everyone else: watch for a city statement or a state AG filing. Until one appears, RansomHouse's claim is a claim.

Sources: RansomHouse Targets City of McMinnville, Oregon - DeXpose | Minnesota Water Cyber Attack and CISA Advisory AA26-097A | Minnesota Epilepsy Group; Campbell University; City of Middletown A... | City of McMinnville Oregon Becomes Latest Target in Growing RansomH... | Middletown, OH warns 123,000+ people of data breach that leaked SSN... | Megan Simmons | The City of New Britain Data Breach Lawsuit - Class Action U | City of Saint Paul Data Breach Emery Reddy