Ransomware victim disclosure
← All victimsThe City of Hesperia, CA
Claimed by Incransom · listed 3 months ago
Status timeline
- ListedMar 4, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Sector
- Public Sector
- Listed on leak site
- Mar 4, 2026
About the victim
AI dossier — public-source company profileThe City of Hesperia is a incorporated municipality in San Bernardino County, California, incorporated in 1988. It provides local government services including public works, planning, law enforcement coordination, and community development to a population of approximately 100,000 residents in the High Desert region.
- Industry
- Municipal Government
- Address
- 9700 Seventh Ave, Hesperia, CA 92345, United States
- Employees
- 201-500
- Founded
- 1988
Attack summary
Severity: critical — Confirmed exfiltration and publication of regulated PII (employee and government official personal data), financial records, and sensitive government documents from a municipal government entity, representing a broad compromise of both personal and governmental sensitive data.The Incransom group claims to have exfiltrated files containing sensitive government records including NDAs, contracts with public and private entities, personal data of employees and government officials, and financial documents including transactions, payment records, and tax documents; data has been published.
Data the group says was taken
AI dossier — extracted from the leak post- Non-disclosure agreements
- Government contracts
- Personal data of employees
- Personal data of government officials
- Transaction records
- Payment documents
- Tax documents
- State secrets / sensitive government files
What the group claims
Access was gained to files containing state secrets, non-disclosure agreements, contracts with private and public companies, as well as personal data of employees and government officials. Transactions, payment, and tax documents were also obtained.
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

