Rhysida claimed 6.5TB of data from the City of Columbus ransomware attack

Organization
City of Columbus, Ohio
Exploit
Ransomware
Industry
Municipal Government

The City of Columbus, Ohio detected an intrusion on July 18, 2024 that forced it to take a range of online services offline. The city's Department of Technology severed internet connectivity to contain the intrusion, and officials said the step prevented the attackers from encrypting municipal systems, though it did not stop data being copied out. The city described the incident publicly as a cybersecurity incident and did not say ransomware had been attempted until an update it published on July 29, 2024.

The Rhysida group claimed responsibility and listed the city on its leak site, saying it held 6.5 terabytes of material including employee logins and passwords, city databases, server dumps, emergency services records and access to municipal video cameras. Rhysida sought a ransom of close to $2 million and attempted to auction the data twice, on July 31 and again on August 8, 2024. Both auctions failed and the group began publishing files instead.

Mayor Andrew Ginther initially said the stolen data appeared corrupted and unusable. Security researcher David Leroy Ross publicly disputed that, saying personal information on hundreds of thousands of residents was accessible on the dark web. The city sued Ross in late August seeking $25,000 in damages and obtained a temporary restraining order, later replaced by a narrower injunction restricting his distribution of sensitive material.

The FBI and the Department of Homeland Security assisted the investigation. Columbus ultimately notified about 500,000 people that their personal and financial information had been taken.

Sources