McMinnville Data Breach: 53K Visits to Leaked Records | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


A McMinnville, Oregon cybersecurity specialist says he needed just three clicks to reach a trove of sensitive city records sitting on the dark web, months after the City of McMinnville first noticed something wrong on its network. The discovery, reported October 1, 2026 by KOIN 6 News and local Fox affiliate KPTV, has turned a routine municipal breach notice into a live case study in how slowly local governments move when ransomware crews start publishing stolen files for anyone to grab.

The city of roughly 34,300 people, the seat of Yamhill County, confirmed that unauthorized access to its systems occurred between June 1 and July 18, 2026. It did not say so publicly until September 29, more than ten weeks after it first spotted the intrusion. In between, a ransomware group calling itself RansomHouse posted what it described as proof of stolen McMinnville files on its leak site, and at least one resident with professional security training went looking for himself.

Google · Preferred Sources

Don’t miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

What happened in McMinnville, Oregon

According to the city’s own breach notification, officials detected unusual activity on their network on July 15, 2026, and brought in outside investigators to figure out what had happened. That investigation eventually determined that an intruder had accessed and copied certain information between June 1 and July 18, a window of roughly six and a half weeks during which the city says it was unaware anything was wrong until the final days.

The city’s formal notice, issued September 29 and reported by KPTV, says the exposed information could include a name, driver’s license number, and/or Social Security number. That is the narrow, legally required disclosure. What a local cybersecurity specialist found when he went looking on the dark web paints a considerably broader picture, and that gap between the official notice and what was actually sitting online is the part driving the story now.

This is not McMinnville’s first brush with a high-profile breach notice this year. tech-insider.org has tracked a wave of similar municipal and institutional disclosures in 2026, including the Arizona court system’s exposure of roughly 150,000 foster-care files and the Pentagon DMDC breach affecting an estimated 3.05 million military records. Government networks, run on tight budgets with legacy systems, keep turning up as soft targets.

Who found the leak: Chuck Dornon’s dark web discovery

The specialist at the center of the story is Chuck Dornon, CEO of the McMinnville-based security firm Alexonet and a resident of the city himself. According to the reporting syndicated by Yahoo News from KOIN, Dornon has been monitoring dark web leak sites since he first learned of the city’s breach on August 6, 2026, the same day RansomHouse listed McMinnville as a victim.

Dornon told KOIN that reaching the city’s leaked files required almost no effort. “Three clicks. That’s all it took to reach private McMinnville records that should never have been public on the dark web,” he said, according to the KOIN report syndicated on Yahoo News. He described the scale of what he found in similarly blunt terms: “There’s a treasure trove of information that’s out there, that should have been protected a little bit better.”

By his count, the leak site hosting the McMinnville files had logged 53,000 visits as of late September, a figure he has been tracking since he first located the data. That number says nothing about how many people actually downloaded sensitive records, but it is a rough proxy for how much attention the leak has drawn since RansomHouse posted it.

What data was actually exposed

The contrast between the city’s official notice and Dornon’s own review of the leaked files is the most consequential detail in this story. McMinnville’s notice tells residents to watch for exposure of their name, driver’s license number, and Social Security number. That is the legal baseline for triggering a breach notification under Oregon’s identity-theft law.

Dornon’s own review, described to KOIN, goes well beyond that. He says he found tax returns, stored passwords, bank records, and human resources files mixed in with the leaked data. He also says the files included confidential police records, what appeared to be witness interview material from criminal investigations, medical information, and municipal court records. If accurate, that combination would cut across nearly every department in a small city government: finance, HR, the police department, and the municipal court.

That is a materially different risk profile than a typical consumer breach. Leaked police witness statements and confidential investigative material carry safety implications that go beyond the usual identity-theft and credit-fraud concerns tied to a stolen Social Security number. It also raises questions about whether the city’s public notice adequately captured the scope of what was actually taken, a question KPTV said it had put to the city without yet getting department-by-department detail back.

The RansomHouse connection

The group behind the leak, RansomHouse, is not a new name in the ransomware world. According to threat-intelligence profiles from Halcyon, RansomHouse emerged as a ransomware-as-a-service operation in late 2021 and is linked to a threat cluster tracked under the name Jolly Scorpius. The group runs a classic double-extortion playbook: steal data first, then either encrypt systems, publicly shame non-paying victims, or both.

RansomHouse has built a reputation for targeting mid-size organizations across healthcare, finance, transportation, and government, the same mix of soft, under-resourced targets that keep appearing across 2026’s breach headlines. It listed the City of McMinmville on its leak site on August 6, 2026, posting what it characterized as proof of exfiltrated internal files.

Government-sector victims like McMinnville are a recurring theme for groups running this playbook, largely because municipal IT departments tend to carry the same aging infrastructure and thin security staffing that made cities like Atlanta and Baltimore high-profile ransomware casualties in the late 2010s. The tools and tactics have changed since then, but the underlying weak point, under-funded local government IT, has not.

Timeline: from “unusual activity” to public notice

Laid end to end, the sequence of events in McMinnville looks like this:

DateEvent
June 1, 2026Earliest date the city says unauthorized access may have begun
July 15, 2026City detects “unusual activity” on its network, launches investigation
July 18, 2026Last date of the window in which data may have been copied without authorization
August 6, 2026RansomHouse lists City of McMinnville on its dark web leak site; Chuck Dornon learns of the breach
September 22, 2026City says its forensic investigation is “in-part complete”
September 29, 2026City issues formal breach notice, begins mailing letters to residents
October 1, 2026KOIN and KPTV publish detailed reporting on the breach and the dark web exposure

What stands out is the roughly seven-week gap between discovery on July 15 and the leak site posting on August 6, followed by nearly another two months before the city’s formal public notice went out on September 29. For a breach that a resident with no special law-enforcement access could apparently find and browse within three clicks, that is a long runway for the city to control the narrative before informing the people whose data was exposed.

Why McMinnville’s response took so long

Oregon’s Consumer Identity Theft Protection Act, enforced through the state Department of Justice, generally requires organizations to notify affected individuals within a defined window after discovering a breach, a rule the state DOJ’s own consumer protection office publishes guidance on. Dornon has publicly argued that McMinnville’s timeline, from a July 15 discovery to a September 29 notice, a stretch of roughly 76 days, exceeds what the law allows, a claim echoed by the Yamhill County outlet yamhillae.com in its own questioning of the city’s compliance.

The city has not publicly detailed why the gap between discovery and notice ran as long as it did, beyond describing its investigation as having reached only a partial conclusion by September 22. That is a familiar pattern in ransomware cases: forensic investigations into exactly what was taken and who was affected routinely take weeks or months, and organizations often wait for a fuller picture before notifying residents, even when state law sets tighter deadlines. The tension between “notify fast” and “notify accurately” is one of the more persistent headaches in breach response, and it is exactly what is playing out in Yamhill County right now.

How this compares to other 2026 data breaches

McMinnville is a small city, but its breach fits a pattern that has repeated across sectors throughout 2026. Here is how it stacks up against other recent breaches tech-insider.org has covered, measured by what is publicly known about scale and the type of data exposed.

IncidentSectorPeople/records affectedData exposed
City of McMinnville, ORMunicipal governmentNot yet disclosed by the cityNames, SSNs, driver’s license numbers; plus police, court, medical, HR and financial files per outside researcher
Pentagon DMDC breachFederal government~3.05 millionMilitary personnel records
Arizona court systemState judiciary~150,000Foster-care case files
OneMain FinancialConsumer lending16,988+Financial and personal records
Labcorp (Wisconsin settlement)Healthcare/laboratory16,615Lab and medical records

What sets McMinnville apart is not scale, it is almost certainly the smallest breach by raw record count on this list, but the breadth of record types in one place. Police investigative files, municipal court records, HR data, and personal financial information rarely sit on the same compromised server in a breach this size. That concentration is part of why Dornon called it “a treasure trove,” a description that fits a small-city network where departments that would normally be siloed, police, courts, HR, finance, often end up sharing infrastructure to save money.

Market and industry impact: why municipal breaches hit differently

Breaches at private companies tend to resolve into a familiar playbook: credit monitoring offers, a class-action settlement a year or two later, and a line item on a 10-K. Municipal breaches are messier, because the victim organization is also the one responsible for policing, courts, and public records, and because residents cannot simply switch providers the way they might cancel a credit card or change banks after a retailer breach.

For the cybersecurity industry, incidents like McMinnville’s are a recurring argument for dark web monitoring as a baseline control rather than an optional add-on, since it was exactly that kind of monitoring that let an independent researcher find the leak well before the city’s own public notice went out. tech-insider.org has previously covered how organizations are building out that capability in practice, including a step-by-step look at setting up dark web monitoring programs and the broader push toward reducing unused access and entitlement risk inside government and enterprise networks alike.

There is also a vendor-side angle. Breach-notification and class-action lead-generation sites exist specifically because incidents like this one generate a predictable aftermath: residents searching for whether their data was part of a leak, followed eventually by law firms testing the waters for litigation. That ecosystem has grown large enough to be its own minor industry, tracking everything from this kind of municipal exposure down to breaches at single regional lenders.

Historical context: ransomware’s long run at local government

Ransomware groups have been hitting American city governments for close to a decade, going back to the headline-grabbing attacks on Atlanta and Baltimore in the late 2010s, both of which forced city departments offline for weeks and became case studies in how expensive recovery can get once a municipal network goes down. What has changed since then is less the target selection than the extortion model: groups like RansomHouse increasingly skip or supplement encryption with straight data theft and public leak-site shaming, calculating that the threat of exposed police files and resident records is leverage enough on its own.

That shift matters for how a city like McMinnville experiences a breach. A pure encryption attack locks a city out of its own systems, a visible, immediate crisis that forces fast public acknowledgment. A quiet exfiltration followed by a leak-site posting two months later is the opposite: invisible to residents until someone like Dornon goes looking, and far easier for an under-resourced IT department to sit on while it works out exactly what was taken.

What McMinnville residents should do now

The city has set up a dedicated assistance line, 1-833-544-7562, staffed Monday through Friday from 5 a.m. to 5 p.m. Pacific time, for residents who want to know whether their information was part of the breach but have not received a mailed notice. The city’s official statement, as reported by KPTV, reads in part: “McMinnville takes this incident and security of personal information in its care very seriously.”

Beyond calling that line, security practitioners generally recommend the same baseline steps after any breach involving a Social Security number or driver’s license number: placing a fraud alert or credit freeze with the major credit bureaus, watching bank and credit statements closely for the next several months, and treating unexpected calls or emails referencing the breach with suspicion, since breach notices themselves are a favorite lure for follow-up phishing attempts. The Federal Trade Commission’s data on identity theft consistently shows that breach-adjacent scams spike for months after a notification goes out, as scammers impersonate the breached organization itself.

Given what Dornon says he found in the leaked files, including what appears to be medical information and HR records, affected city employees may face a broader set of risks than the general public, up to and including targeted social-engineering attempts that reference real internal details pulled straight from the leak.

The bigger pattern: why this keeps happening to small cities

McMinnville is not an outlier so much as a predictable data point. Verizon’s long-running Data Breach Investigations Report has for years flagged the public sector as disproportionately exposed to breaches involving stolen credentials and slow detection, a pattern that tracks closely with what happened here: a roughly six-and-a-half-week window of undetected access followed by a multi-week gap before public disclosure.

Small city governments rarely have the budget to run the kind of layered detection and dark web monitoring that let an outside researcher find this leak before the city’s own notice went out. That gap between what a motivated private citizen can find with free tools and what a municipal IT department detects on its own network is, in miniature, the entire argument for why breach-detection spending keeps climbing across both the public and private sectors.

Predictions: what happens next

Based on how similar municipal breaches have played out this year, a few things look likely in the weeks ahead:

  • McMinnville will likely face continued pressure, from residents, local media, and possibly the Oregon DOJ, to disclose a specific number of affected individuals rather than the general category language in its current notice.
  • Expect breach-tracking and class-action intake sites to open investigations tied to the McMinnville incident in the coming weeks, following the same pattern seen after the Pentagon DMDC and Arizona court breaches.
  • RansomHouse will almost certainly continue targeting small and mid-size government networks, given the group’s multi-year track record of hitting under-resourced public-sector victims.
  • Other Oregon municipalities will likely face renewed scrutiny over their own compliance with the state’s breach-notification timelines, given the attention this case has drawn to the 45-day question.
  • Dark web monitoring services aimed at local governments are likely to see increased interest from Pacific Northwest municipalities watching this story unfold.

Frequently asked questions

What happened in the McMinnville, Oregon data breach?

The City of McMinnville detected unusual network activity on July 15, 2026, and later determined that an intruder had accessed and copied certain data between June 1 and July 18, 2026. The ransomware group RansomHouse listed the city on its dark web leak site on August 6, 2026, and the city issued a formal public notice on September 29, 2026.

Who discovered the exposed McMinnville records online?

Chuck Dornon, CEO of the McMinnville-based cybersecurity firm Alexonet and a city resident, located the leaked files on the dark web and reported that reaching them took only three clicks.

What kind of data was exposed in the McMinnville breach?

The city’s official notice cites names, driver’s license numbers, and Social Security numbers. According to the cybersecurity specialist who reviewed the leaked files, the exposure also appeared to include tax returns, passwords, bank records, HR files, confidential police records, witness interview material, medical information, and municipal court records.

Is RansomHouse a known ransomware group?

Yes. RansomHouse is a ransomware-as-a-service operation that emerged in late 2021 and runs a double-extortion model, stealing data and threatening to leak it publicly. Security researchers have linked the group to a broader threat cluster and noted it frequently targets government, healthcare, finance, and transportation organizations.

Did McMinnville notify residents within Oregon’s legal deadline?

That is disputed. Dornon and at least one local outlet have argued the city’s roughly 76-day gap between discovery and public notice exceeded Oregon’s breach-notification requirements. The city has not publicly addressed the specific timeline question beyond describing its investigation as reaching only a partial conclusion by September 22.

How can affected McMinnville residents get more information?

The city has set up a dedicated assistance line, 1-833-544-7562, available Monday through Friday from 5 a.m. to 5 p.m. Pacific time, for residents who want to confirm whether their information was involved, including those who have not received a mailed notice.

How many people were affected by the McMinnville data breach?

As of the city’s September 29 notice and subsequent reporting, McMinnville had not publicly disclosed a specific number of affected individuals.

How does the McMinnville breach compare to other 2026 government data breaches?

It is smaller in raw record count than incidents like the Pentagon DMDC breach or the Arizona court system’s foster-care file exposure, but notable for the breadth of sensitive record types, spanning police, court, HR, medical, and financial data, apparently stored and compromised together.

Related Coverage

Sofia Lindström

Editor-in-Chief

Sofia Lindström is the Editor-in-Chief at Tech Insider, where she leads editorial strategy and oversees coverage across AI, cybersecurity, and enterprise technology. With over a decade in Swedish tech journalism, she previously served as technology editor at Dagens Industri and covered the Nordic startup ecosystem for Breakit. Sofia holds an MSc in Media Technology from KTH Royal Institute of Technology and is a frequent speaker at Web Summit and Slush. She is passionate about making complex technology accessible to business leaders.

View all articles

——————————————————–


Click Here For The Original Source.

.........................