City of McMinnville OR Data Breach

Alleged

Ransomware claim involving City of McMinnville OR

Published: Aug 6, 2026 RansomHouse
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
City of McMinnville OR
Industry
Defense
Threat Actor
RansomHouse
Date of Incident
Aug 6, 2026

Executive Summary

City of McMinnville OR, a municipal government body operating within the government and defense sector in the United States, has been identified as a victim of the RansomHouse ransomware group. The listing appeared on the group’s dark web portal on August 6, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. As a public-sector entity responsible for essential services, any disruption to its operations would be immediately noticeable to its residents. This incident marks another instance of RansomHouse targeting public sector organizations, with several similar listings appearing within the same timeframe. In the 60 days preceding this listing, RansomHouse claimed a total of nine other victims. The group has demonstrated a consistent pattern of targeting organizations within the government and defense, manufacturing, and financial services sectors. Geographically, the majority of their victims are located in the United States, with notable presences in Panama and Canada as well. Recent victims that share similar characteristics with the City of McMinnville OR, such as other U.S. government entities, include the City of Beacon, lya Construtora, TECHVENTURES BANK S.A., and PCL Holding. The concurrent listing of two U.S. municipalities on the same day is a noteworthy occurrence for a group that does not typically have a high volume of published victims, suggesting a potentially coordinated targeting effort.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry did not yield any records associated with the domain mcminnvilleoregon.gov within the queried sample. It is crucial to understand that a negative result from a specific query does not definitively confirm the absence of a compromise. The telemetry examined represents a paginated sample from a single dataset. Compromises linked to alternate corporate domains, contractor-managed subdomains, or credentials utilizing personal email aliases on municipal systems would not be reflected in this specific search. Municipal environments, in particular, often rely on centralized authentication systems managed at the county or state level, which can exist outside the primary organizational domain, thus limiting the visibility of a single-domain query. Ransomware groups like RansomHouse commonly exploit infostealer-harvested credentials as an initial access vector. Threat actors or initial access brokers typically source recent credential logs from underground marketplaces, validate their authenticity for corporate accounts, and then use them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. The lack of evidence in this particular query does not preclude this scenario. It is possible that compromised credentials exist within datasets not covered by this search, were used and subsequently rotated before being indexed, or were harvested using personal email aliases. Therefore, CTI teams should prioritize continuous monitoring and proactive credential hygiene checks over interpreting a null query as confirmation of no compromise.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.