Ohio History Connection ransomware attack exposed data on about 7,600 people

Organization
Ohio History Connection
Exploit
Ransomware
Industry
Nonprofit

Ohio History Connection, the nonprofit that runs Ohio's state archives and more than 50 historical sites, disclosed that a ransomware attack in early July 2023 encrypted its internal data servers and exposed personal information belonging to roughly 7,600 people.

The organisation said the exposed data included names, addresses and Social Security numbers of current and former employees covering 2009 to 2023, W-9 forms and Social Security numbers belonging to contracted vendors, and images of cheques from members and donors dating from 2020 onward. It said no credit card information was accessed and that it had no evidence the data had been misused.

Ohio History Connection confirmed that it made a counter-offer to the attackers in an attempt to keep the material from being published. The attackers rejected that offer on August 7, 2023, after which the nonprofit warned that the information might now be accessible to anyone looking for it. It did not name the group responsible. ThreatDown reported that the stolen data appeared on LockBit's leak site, and The Record reported that a phishing email with a malicious attachment was the suspected entry point, which the organisation did not confirm.

The nonprofit notified the FBI, engaged a forensic IT consultancy and mailed notification letters in late August 2023, offering those affected a year of free credit monitoring through IDX along with a support hotline. It said it had since migrated most of its data to cloud services and added new security systems.

Sources