Quick Summary
AllegedExecutive Summary
Merrimack County, a governmental entity in New Hampshire responsible for public administrative services, including justice and social services, was listed on the Booba Project ransomware group’s dark web portal on September 23, 2026. The discovery was made via SOCRadar’s Dark Web Monitoring service. Coincidentally, Washington County, another US county government, was also claimed by Booba Project on the same date, suggesting a potential coordinated attack targeting county-level public infrastructure. Such entities are often targeted due to perceived resource constraints in their cybersecurity defenses. In the 60 days preceding this incident, Booba Project claimed 14 other victims. Their primary target sectors include Government & Defense and Professional Services, with the United States being the most frequently targeted country, followed by Italy and Moldova. Previous public sector victims listed by the group include Washington County, Tulare Western High School, Atlas Ocean Voyages, and Mestechkin Law Group P.C. This consistent focus on county-level governments highlights a persistent strategy by Booba Project to exploit vulnerabilities in under-resourced public sector organizations.
Technical Analysis
A query for the domain merrimackcounty[.]net returned no records within the SOCRadar-monitored dataset. This absence of positive signals indicates no direct detection of credentials associated with this specific domain in the queried data. However, it is important to note that government domains often have less comprehensive coverage in commercial infostealer feeds compared to corporate targets. Compromised credentials may exist under alternative municipal subdomain variants or personal email aliases used by county staff, which might not be captured by standard monitoring. The Booba Project’s established modus operandi of leveraging infostealer-harvested credentials for VPN access as an initial access vector remains a plausible scenario for this incident, irrespective of the current null result. The lack of evidence in this specific dataset does not rule out the possibility of a compromise. Government entities are advised to consider continued monitoring of the dark web and infostealer feeds, paying close attention to any associated subdomains or alternative email formats used by their personnel. Continued monitoring of dark web activity and proactive credential hygiene checks across all county staff accounts are recommended measures for Merrimack County.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.