US Cities Show Up on Ransomware Leak Sites
ransomware.live lists several U.S. local governments as alleged victims, while Minnesota says a coordinated attack hit more than 30 water systems.
ransomware.live listed Greene County, the City of Atlanta, Houston, West Chester Township and the Town of Vienna as alleged victims. Meanwhile, Minnesota confirmed a coordinated, ransom-free attack on more than 30 water systems.
U.S. municipalities on leak sites
The ransomware.live portal has added several entries in its Government & Defense, US section pointing to U.S. local governments as alleged ransomware victims. Among them is Greene County, Georgia, tied to the greenecountyga.gov domain and listed as a target of the Incransom group, with a discovery date of July 28, 2026.
The same record also lists the City of Atlanta as a victim published by Exfilsquad, with a discovery date of July 26, 2026. The City of Houston is also named as a victim attributed to the same group in the Government & Defense category, although the portal does not give an exact attack date or say whether there has been public confirmation from local officials.
The list also includes West Chester Township, Ohio, described as the most populous municipality in that state, which suggests a presumed intrusion into its local administration. The Town of Vienna, Virginia, appears in the same category as another victim listed by a ransomware group. On RansomLook.io, meanwhile, the recent posts index shows an entry marked [DISCLOSED] Prince George County, attributed to a ransomware group, indicating data exposure or an extortion attempt against that county.
In Houston’s case, ransomware.live adds more detail. The attack attributed to Exfilsquad is said to have taken place on July 26, 2026, with discovery the same day, and the leak would affect 18 employees and 721 compromised users. That entry reinforces the profile of an information theft campaign and possible extortion effort against a local government.
Minnesota, a ransom-free attack
While those listings point to alleged extortion campaigns, Minnesota reported a different kind of incident. Minnesota IT Services confirmed a coordinated cyberattack that affected more than 30 community water systems on July 26 and 27, 2026, with cases reported in Braham, Maple Plain, South St. Paul and Plymouth.
MNIT said it detected similarities in the timing of the attacks, the access methods and the target infrastructure. It also said there was no official attribution for the attackers and no ransom demands had been reported. The investigation was still active at least through July 29.
Local authorities provided more detail on the impact. Braham said its water plant was out of service for several hours on Monday, July 27, after a malicious attack on computerized operational systems carried out by unknown actors, which shut down operational controls. Service was restored and the city said the water remained safe to drink.
Plymouth, South St. Paul and Braham also said their facilities were targeted the same day, with impacts to water towers, pumping stations and the drinking water system. In all cases, officials said residents could continue using the water normally and there were no signs of contamination.
Technical and mainstream coverage agreed that the incident affected industrial control infrastructure and automated water and wastewater systems, causing temporary outages at plants and pumping systems, but without the data encryption typical of ransomware or any associated financial extortion. TecMundo also said the response included the deployment of a state cybersecurity task force to help mitigate damage across more than 30 supply systems.
Context and attribution
The question of who was behind Minnesota’s attack remains open. A report from La Tercera, citing The New York Times and state officials, said about 36 municipal water systems may have been targeted and that Iranian hackers are suspected, although that attribution remains unconfirmed.
That backdrop matches a joint alert updated on July 23, 2026 by the FBI, NSA, CISA, the Department of Energy and Cyber Command, which warned about activity from Iranian state-linked actors against industrial control systems at water and energy facilities. The notice cited operational disruptions and recommended protecting PLCs, segmenting OT and IT networks, and strengthening credentials. In parallel, Xakep summed up that technical and mainstream outlets agree the Minnesota case did not show a direct link to known ransomware campaigns.
City of Quitman, what details are available about the ransomware attack?
The material available does not include specific details about the City of Quitman. What it does show is that ransomware.live is listing several U.S. local governments as alleged victims, with varying levels of detail depending on the entry.
The same category includes Greene County, Georgia, the City of Atlanta, the City of Houston, West Chester Township, Ohio, the Town of Vienna, Virginia, and Prince George County. In some cases, the portal lists the attributed group, discovery date and, for Houston, a claimed impact on employees and compromised users.
Sources
- EEUU alerta: hackers iraníes vinculados al IRGC están comprometiendo sistemas de agua y energíawwwhatsnew.com· WWWhat's New
- Cyberattacks target several Minnesota water facilities, state officials sayfox9.com· FOX 9 Minneapolis-St. Paul
- Ciberataque coordinado afectó a más de 30 sistemas de agua en Minnesotablog.nivel4.com· Nivel4
- Estados Unidos sospecha que Irán pudo estar tras el ciberataque a los sistemas de agua de Minnesotalatercera.com· La Tercera
- Coordinated Cyberattack Targets 30+ Minnesota Water Systemsthehackernews.com· The Hacker News
- Government & Defense — USransomware.live· ransomware.live
- Ataque cibernético coordenado atinge 30 estações de água nos Estados Unidos e mobiliza força-tarefatecmundo.com.br· TecMundo
- Victim: City of Houston @ Exfilsquadransomware.live· ransomware.live
- Recent posts (incluye entrada [DISCLOSED] Prince George County)ransomlook.io· RansomLook.io
- "Coordinated cyberattack" targeted 30-plus Minnesota water systems; malware shut down Braham water plantcbsnews.com· CBS News Minnesota
- Более 30 объектов водоснабжения в США пострадали от скоординированной кибератакиxakep.ru· Xakep



