Quick Summary
AllegedExecutive Summary
Greene County, Georgia, a local government entity in the United States, has been listed as a victim by the INC Ransom ransomware group. The listing was identified by SOCRadar’s Dark Web Monitoring service on July 28, 2026, and places the county within the government and defense sector. While government is not INC Ransom’s most frequently targeted industry, the group’s operations show a strong presence in the United States, making this listing consistent with their geographic focus. In the 60 days preceding this listing, INC Ransom claimed 33 other victims, primarily targeting business services, manufacturing, and general or uncategorized organizations. Recent U.S. victims highlighted by the group include The HOP, Foundations to Freedom, Ali-Monde, and VantagePoint Management & Autoclear. While Greene County aligns with INC Ransom’s dominant U.S. geography, its classification as a government entity represents a less frequently targeted vertical compared to the business services and manufacturing sectors that the group typically focuses on.
Technical Analysis
A review of stealer-log data for the domain greenecountyga[.]gov yielded no records within the queried dataset. It is important to note that this query was limited to a paginated and partial sample. Therefore, the absence of observed records does not preclude the possibility of credentials existing under alternate corporate domains, or being associated with employee personal email aliases that were not included in the search parameters. Such findings represent an absence of evidence, not evidence of absence, regarding a potential compromise. The INC Ransom group commonly employs a strategy of acquiring infostealer-harvested credentials to gain initial access. Threat actors or initial access brokers then validate these credentials to infiltrate systems, often targeting Microsoft 365, Virtual Private Networks (VPNs), or other remote-access portals. This initial access is subsequently leveraged for ransomware deployment. Consequently, even without directly observed compromised credentials for Greene County, this methodology means that a confirmed safety status cannot be established. The current lack of visible stealer-log records for Greene County, Georgia does not rule out the possibility of compromise. Infostealer logs may exist in feeds outside the currently queried dataset, credentials might have been used and subsequently rotated before indexing, or the data may not yet have been indexed. Therefore, continued monitoring for freshly indexed credentials and proactive credential-hygiene checks across all county accounts are recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.