Ransomware victim disclosure
← All victimsCity of Atlanta
Claimed by ExfilSquad · listed 3 days ago
Status timeline
- ListedJul 26, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Country
- United States
- Sector
- Government & Defense
- Listed on leak site
- Jul 26, 2026
About the victim
AI dossier — public-source company profileThe City of Atlanta is the capital and most populous city of Georgia, providing municipal services including public safety, utilities, permitting, licensing, and citizen services to over 500,000 residents. It operates as a full-service local government entity with extensive digital infrastructure for case management and civic records.
- Industry
- Municipal Government & Public Administration
- Address
- City Hall, 55 Trinity Avenue SW, Atlanta, Georgia 30303, USA
- Employees
- 5000-10000
- Founded
- 1837
Attack summary
Severity: critical — Confirmed exfiltration of ~3 million records containing PII, addresses, and municipal case data affecting a major US city's residents and operations. This represents large-scale exposure of regulated personal data with direct impact on citizen privacy and potential identity theft risk.ExfilSquad claims to have exfiltrated approximately 3 million records from City of Atlanta's systems containing sensitive personally identifiable information, citizen addresses, service requests, and internal case management data. The group has published data but no ransom demand was announced.
Data the group says was taken
AI dossier — extracted from the leak post- Citizen PII (names, identifiers)
- Residential addresses
- Citizen service requests
- Municipal case history
- Internal case management records
What the group claims
DATA SUMMARY: 3M~ records containing: significant PII, citizen service requests, addresses, municipal case history, and internal case management data.
Sources
- Victim siteatlantaga.gov
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

