
A ransomware attack in July has compromised the personal information of around 500,000 Columbus, Ohio, residents, making it one of the largest cyber incidents to impact a U.S. city. The breach, attributed to the Rhysida ransomware group, has raised concerns not only for the extent of data compromised but also due to the city’s contentious response, particularly its legal action against a cybersecurity researcher.
The July 18 attack prompted Columbus officials to shut down critical systems to prevent further data loss, causing disruptions in city services. Initial statements from officials indicated that only corrupted and unusable data was accessed. However, Rhysida claimed it had exfiltrated 6.5 terabytes of data containing sensitive details such as Social Security numbers, addresses, bank account information, and driver’s license data. After ransom negotiations failed, Rhysida released 3.1 terabytes of this information on the dark web.
City officials later confirmed that a considerable volume of data had been leaked, including information from law enforcement and city employee databases. Rhysida, known for using double-extortion tactics, encrypts and threatens to publish sensitive information unless ransom demands are met. In this case, when negotiations stalled, the group posted portions of the data, which remains accessible to unauthorized users on its dark website.
The incident intensified when cybersecurity researcher David Leroy Ross, also known as Connor Goodwolf, publicly disclosed details about the leak, including information contradicting the city’s initial statements. Ross claimed the stolen data was unencrypted and included extensive sensitive information, countering the city’s assurances that accessed data was “unusable.” In response, Columbus officials filed a lawsuit against Ross in early August, accusing him of unlawfully sharing and accessing the stolen data.
City Attorney Zach Klein defended the lawsuit, stating it aimed to protect resident privacy and prevent unauthorized distribution of the exposed information. Critics, however, argue that the legal action could deter future transparency in cyber incident reporting. Some observers believe the move could potentially chill cybersecurity research crucial in revealing data vulnerabilities to the public.
Following the breach, Columbus notified the Maine Attorney General’s Office, adhering to legal requirements, and provided affected residents with two years of complimentary credit monitoring and identity protection. The city has also pledged to bolster its cybersecurity infrastructure but has not provided specific details.
Rhysida, a ransomware-as-a-service (RaaS) group first identified in May 2023, allows affiliates to use its ransomware for a share in ransom profits. The group targets a wide range of sectors globally, including government, healthcare, and education, often exploiting weaknesses in remote systems and stolen credentials for access.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543