Charlottesville Police Department Data Breach

Alleged

Ransomware claim involving Charlottesville Police Department.

Published: Sep 21, 2026
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Charlottesville Police Department
Industry
Government
Date of Incident
Sep 21, 2026

Executive Summary

Doommageddon ransomware has listed the Charlottesville Police Department, a municipal law enforcement agency based in Virginia, on its dark web portal. This listing was identified by SOCRadar’s Dark Web Monitoring. In the preceding 60 days, Doommageddon had claimed only three other victims, with these scattered across Turkey, the United States, and India. The targeting of the Charlottesville Police Department represents the group’s most significant claim against a US government sector entity to date. While Doommageddon’s operational tempo appears low, with only four claimed victims in the last 60 days, a claim against a law enforcement agency is notable due to the sensitive nature of data typically handled by such organizations. The group’s previous victims include INCOR Group, Akpera Gayrimenkul Yatırım A.Ş., and SITTNAK Lojistik A.Ş. The limited recent activity does not diminish the potential impact of targeting a police department, which may hold personal, investigative, and operational data.

Technical Analysis

A query against the domain cpdcareers[.]com, which is associated with the Charlottesville Police Department’s careers website, returned no records. It is important to note that this specific domain is designated for recruitment and may not represent the primary operational infrastructure of the police department. Consequently, searches conducted on the department’s core operational domains or internal VPN endpoints could potentially yield different results. The absence of records on the careers domain does not preclude the possibility of a compromise affecting other areas of the Charlottesville Police Department’s infrastructure. Threats actors often target specific subdomains or less protected entry points. Therefore, continued monitoring across all known domain variants associated with the department is recommended to detect any further compromise indicators. Monitoring should continue across all known domain variants associated with the Charlottesville Police Department.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.