CiberLATAMbywhalemate

US Cities Show Up on Ransomware Leak Sites

ransomware.live lists several U.S. local governments as alleged victims, while Minnesota says a coordinated attack hit more than 30 water systems.

Whalemate Labs · AI-assisted researchJul 31, 20263 min read

ransomware.live listed Greene County, the City of Atlanta, Houston, West Chester Township and the Town of Vienna as alleged victims. Meanwhile, Minnesota confirmed a coordinated, ransom-free attack on more than 30 water systems.

U.S. municipalities on leak sites

The ransomware.live portal has added several U.S. local governments to its Government & Defense category, under the U.S. section, as alleged ransomware victims. Among them is Greene County, Georgia, with the domain greenecountyga.gov, listed as an Incransom target with a discovery date of July 28, 2026.

The same record also names the City of Atlanta as a victim published by Exfilsquad, with a discovery date of July 26, 2026. The City of Houston is also listed as a victim attributed to the same group in the Government & Defense category, although the portal does not specify the exact date of the attack or say whether the local government has publicly confirmed it.

The list also includes West Chester Township, Ohio, described as the most populous municipality in the state, which points to a suspected intrusion into its local administration. The Town of Vienna, Virginia, appears in the same category as another victim listed by a ransomware group. On RansomLook.io, the recent-post index shows an entry labeled [DISCLOSED] Prince George County, attributed to a ransomware group, indicating data exposure or an extortion attempt against that county.

In Houston’s case, ransomware.live provides more detail. The attack attributed to Exfilsquad is said to have taken place on July 26, 2026, with discovery the same day, and the leak would affect 18 employees and 721 compromised users. That entry reinforces the profile of an information theft campaign and possible extortion against a local government.

Minnesota, an attack without ransom

While those listings point to alleged extortion campaigns, Minnesota reported a different kind of incident. Minnesota IT Services confirmed a coordinated cyberattack that affected more than 30 community water systems on July 26 and 27, 2026, with cases reported in Braham, Maple Plain, South St. Paul, and Plymouth.

MNIT said it detected similarities in the timing of the attacks, the access methods, and the targeted infrastructure. It also said there was no official attribution for the responsible actors and no ransom demands had been reported. The investigation remained active at least through July 29.

Local authorities provided more details on the impact. Braham said its water plant was out of service for several hours on Monday, July 27, after a malicious attack on computerized operating systems carried out by unknown actors shut down operational controls. Service was restored, and the city said the water remained safe to drink.

Plymouth, South St. Paul, and Braham also said their facilities were targeted the same day, affecting water towers, pumping stations, and the drinking water system. In each case, officials said residents could continue using the water normally and that there were no signs of contamination.

Technical and general news coverage agreed that the incident hit industrial control infrastructure and automated water and wastewater systems, causing temporary outages at plants and pumping systems, but without the data encryption typical of ransomware or any associated financial extortion. TecMundo also said the response included the deployment of a state cyber task force to help mitigate damage across more than 30 water supply systems.

Context and attribution

The question of who was behind the Minnesota attack remains open. A La Tercera report, citing The New York Times and state officials, said about 36 municipal water systems may have been targeted and that Iranian hackers are suspected, although that attribution has not been officially confirmed.

That fits a joint alert updated on July 23, 2026 by the FBI, NSA, CISA, the Department of Energy, and Cyber Command, which warned about activity by Iran-linked actors against industrial control systems at water and energy facilities. The notice mentioned operational disruptions and recommended protecting PLCs, segmenting OT and IT networks, and hardening credentials. In parallel, Xakep summarized that technical and mainstream outlets agree the Minnesota case did not show a direct link to known ransomware campaigns.

Sources

View all