
The infamous INC ransomware group has claimed that it hacked into the internal network of the City of McKinney in Texas and stole confidential data.
In a data breach notice posted on its website, the City of McKinney, located in Collin County in Texas, said that on November 14, it identified unauthorised access to its internal network and launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
The investigation revealed that threat actors infiltrated the City’s internal network on October 31. Immediately after identifying the infiltration, the City “severed any unauthorised activity,” took steps to secure the affected systems and notified relevant law enforcement authorities about the incident.
“On November 16, 2024, our investigation determined that certain files may have been exposed without authorisation. Thereafter, the City conducted a thorough review of the contents of the files to determine if they contained any sensitive information.
“On December 30, 2024, after completing the review, the City learned that certain personal or sensitive information contained in its environment may have been exposed as a result of the incident,” the City said.
The compromised data included names and other personal identifiers along with Social Security Numbers. In a filing with the Maine state regulator, the City said it identified at least 17,751 individuals who were impacted by the incident.
🚨 INC RANSOM Ransomware Alert 🚨
— FalconFeeds.io (@FalconFeedsio) February 15, 2025
INC RANSOM Ransomware group has added 2 new victims to their darkweb portal.
• City of McKinney 🇺🇸
• Northeast Delta Human Services Authority 🇺🇸 pic.twitter.com/bLUVMOa4JK
While City officials did not share the nature of the security incident or who was behind the same, the INC Ransom ransomware group recently claimed responsibility for the cyber attack on the City and listed it as a victim on its data leak site. To prove the authenticity of its claims, the group has also shared samples of the stolen data on its dark web forum page.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543