ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

City of St. Paul reveals July 2025 cyber attack compromised data of nearly 15,000 people

The City of St. Paul, Minnesota, said that the data security incident it experienced in July 2025 compromised the sensitive personal information of nearly 15,000 individuals.

 

According to a recent investigation report published on its website, the City of St. Paul said it experienced a cyberattack on July 25 that targeted compromised accounts associated with a critical backup server. In response, city officials immediately deactivated the affected accounts, isolated impacted servers, and implemented enhanced monitoring measures.

 

Following the attack, the City engaged external cybersecurity experts to help contain the threat and conduct a forensic investigation. It also disabled VPN access for most employees as a precaution to prevent further lateral movement by the attacker before shutting down its broader network to contain the breach and remove the threat from its systems. Throughout the incident response, the City worked closely with law enforcement agencies.

 

“On August 11, 2025 a set of data was exposed on the threat actor’s leak site after the City refused to pay a demanded ransom. The exposed material came from a Parks and Recreation network drive, and did not include core city service-related data. The City immediately began a careful review of the data to determine what was accessed and who may have been affected,” city officials said.

 

According to the report, the breach resulted in the theft of approximately 43 GB of data, including the personal information of 12,484 current and former employees, interns, volunteers, and Parks and Recreation program participants.The compromised data included names, addresses, telephone numbers, dates of birth, and Social Security numbers.

 

After completing the review, the city has now started notifying affected individuals as required under Minnesota law.

 

The Interlock ransomware group claimed responsibility for the cyber attack on the City of St. Paul and listed it as a victim on its data leak site. The group claimed to be in possession of 43GB of confidential data stolen from the City and threatened to leak it unless their ransom demand was met.

 

To prove the authenticity of its claim, Interlock also shared sample documents stolen from St. Paul’s private servers.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543