Ransomware victim disclosure
← All victimsMoultrie County Sheriff's Office
listed as moultriesheriff.com · Claimed by Incransom · listed 4 months ago
Status timeline
- ListedFeb 10, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Sector
- Public Sector
- Listed on leak site
- Feb 10, 2026
About the victim
AI dossier — public-source company profileMoultrie County Sheriff's Office is a county-level law enforcement agency in the United States, likely located in Moultrie County, Illinois. It is responsible for policing, detention, and public safety services within its jurisdiction. As a sheriff's office, it handles criminal investigations, civil processes, and local jail operations.
- Industry
- Law Enforcement / Public Safety
Attack summary
Severity: critical — 187 GB of data exfiltrated from a law enforcement agency is highly likely to contain regulated PII, criminal justice records, potentially sensitive investigative data, and information on victims, witnesses, and detainees — all qualifying as regulated/sensitive data at scale from a government entity.The Incransom group claims to have exfiltrated approximately 187 GB of sensitive data from the Moultrie County Sheriff's Office, with the data described as sensitive and the disclosure status listed as data_published.
Data the group says was taken
AI dossier — extracted from the leak post- Sensitive law enforcement records
- Potentially personally identifiable information (PII)
- Potentially inmate/detainee records
- Potentially investigative files
- Potentially personnel records
What the group claims
Sheriff's Office. 187-GB sensitive data
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

