Washington County Data Breach

Alleged

Ransomware claim involving Washington County.

Published: Sep 23, 2026 Booba Project
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Washington County
Industry
Government & Defense
Threat Actor
Booba Project
Date of Incident
Sep 23, 2026

Executive Summary

Washington County, a US-based government entity providing public administration services, was listed on the Booba Project ransomware group’s dark web portal on September 23, 2026. This listing was identified by SOCRadar’s Dark Web Monitoring service. The specific domain associated with the listing is washingtoncountymaine[.]com, indicating the incident pertains to the government of Washington County, Maine. Notably, this listing occurred on the same day as Merrimack County, New Hampshire, suggesting a potential coordinated effort against regional public infrastructure within New England. In the 60 days preceding this listing, Booba Project claimed 14 other victims. The group’s primary targets are in the Government & Defense and Professional Services sectors. Geographically, the United States is the most frequently targeted country, followed by Italy and Moldova. Previous US government victims attributed to this group include Merrimack County, Tulare Western High School, Atlas Ocean Voyages, and Mestechkin Law Group P.C. County governments, often facing constrained security resources, align with the group’s established targeting profile.

Technical Analysis

SOCRadar’s Dark Web Monitoring service queried the domain washingtoncountymaine[.]com for associated infostealer-harvested credentials. The query returned no records. It is crucial to understand that a null result does not definitively confirm the absence of a compromise. Significant coverage gaps exist within commercial infostealer feeds concerning government domains. Exposure may still exist through personal email aliases used by county staff or via subdomain variants that were not included in the queried dataset. The Booba Project’s typical initial access vector involves the exploitation of credentials harvested by infostealers, which are then used to gain access to Microsoft 365 accounts or VPN portals. Given the listing of Washington County, continued monitoring of dark web and stealer-log feeds is recommended. Proactive measures such as credential hygiene checks, password rotation, and a thorough review of multi-factor authentication configurations across all staff accounts are advised to mitigate potential risks.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.