Ransomware victim disclosure
← All victimsCity of Houston
Claimed by ExfilSquad · listed 3 days ago
Status timeline
- ListedJul 26, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Country
- United States
- Sector
- Government & Defense
- Listed on leak site
- Jul 26, 2026
About the victim
AI dossier — public-source company profileThe City of Houston is the fourth-largest city in the United States, operating as a municipal government providing services to residents and businesses. The city government manages departments across public safety, utilities, permitting, health, housing, parks, and 311 citizen service request systems.
- Industry
- Municipal Government & Public Administration
- Address
- Houston, Texas, US
- Employees
- 10000+
- Founded
- 1836
Attack summary
Severity: critical — Confirmed exfiltration of ~6 million records including significant PII (names, addresses, contact details) of city residents at massive scale, combined with operational/service data from a critical municipal government entity. Data already published.ExfilSquad claims to have exfiltrated approximately 6 million records containing significant personally identifiable information (PII) and municipal service data from the City of Houston's systems. The group has published the data.
Data the group says was taken
AI dossier — extracted from the leak post- resident PII
- contact details
- service request records
- complaint descriptions
- home addresses
- location data
- case/ticket metadata
- department routing information
- service status records
- resolution information
- CRM metadata
What the group claims
DATA SUMMARY: 6M~ records containing: significant PII, resident contact details, service requests, complaint descriptions, addresses, location data, case/ticket metadata, department routing, service status, resolution information, and extensive CRM metadata.
Sources
- Victim sitehoustontx.gov
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

