Greene County, Georgia Data Breach

Alleged

Ransomware claim involving Greene County, Georgia

Published: Jul 28, 2026 INC Ransom
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Greene County, Georgia
Industry
Government
Threat Actor
INC Ransom
Date of Incident
Jul 28, 2026

Executive Summary

Greene County, Georgia, a local government entity in the United States, has been listed as a victim by the INC Ransom ransomware group. The listing was identified by SOCRadar’s Dark Web Monitoring service on July 28, 2026, and places the county within the government and defense sector. While government is not INC Ransom’s most frequently targeted industry, the group’s operations show a strong presence in the United States, making this listing consistent with their geographic focus. In the 60 days preceding this listing, INC Ransom claimed 33 other victims, primarily targeting business services, manufacturing, and general or uncategorized organizations. Recent U.S. victims highlighted by the group include The HOP, Foundations to Freedom, Ali-Monde, and VantagePoint Management & Autoclear. While Greene County aligns with INC Ransom’s dominant U.S. geography, its classification as a government entity represents a less frequently targeted vertical compared to the business services and manufacturing sectors that the group typically focuses on.

Technical Analysis

A review of stealer-log data for the domain greenecountyga[.]gov yielded no records within the queried dataset. It is important to note that this query was limited to a paginated and partial sample. Therefore, the absence of observed records does not preclude the possibility of credentials existing under alternate corporate domains, or being associated with employee personal email aliases that were not included in the search parameters. Such findings represent an absence of evidence, not evidence of absence, regarding a potential compromise. The INC Ransom group commonly employs a strategy of acquiring infostealer-harvested credentials to gain initial access. Threat actors or initial access brokers then validate these credentials to infiltrate systems, often targeting Microsoft 365, Virtual Private Networks (VPNs), or other remote-access portals. This initial access is subsequently leveraged for ransomware deployment. Consequently, even without directly observed compromised credentials for Greene County, this methodology means that a confirmed safety status cannot be established. The current lack of visible stealer-log records for Greene County, Georgia does not rule out the possibility of compromise. Infostealer logs may exist in feeds outside the currently queried dataset, credentials might have been used and subsequently rotated before indexing, or the data may not yet have been indexed. Therefore, continued monitoring for freshly indexed credentials and proactive credential-hygiene checks across all county accounts are recommended.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.