Ransomware victim disclosure
← All victimsCullman County, Alabama
listed as co.cullman.al.us · Claimed by Blacksuit · listed 2 years ago
Status timeline
- ListedNov 24, 2024
- Data leakeddate unknown
At a glance
- Group
- Blacksuit
- Status
- Data leaked
- Country
- United States
- Sector
- Government
- Listed on leak site
- Nov 24, 2024
About the victim
AI dossier — public-source company profileCullman County is a local government entity serving a 743-square-mile region in north-central Alabama between Huntsville and Birmingham on Interstate 65. The county provides administrative services, public records, court information, licensing, tax collection, and community alerts to residents and businesses.
- Industry
- Government – County Administration
- Address
- 500 2nd Ave SW, Cullman, AL 35055
Attack summary
Severity: medium — Breach of a county government entity with confirmed data publication, but no detail on specific sensitive data categories (PII, financial records, etc.) is available to assess regulatory impact. Government entity status elevates concern beyond private sector equivalents.Blacksuit claims to have breached Cullman County's website (co.cullman.al.us). The group has published data but no specific details of what was exfiltrated or the scope of the breach are provided in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- public records
- government databases
- county administrative systems
Original description
AI-summarised, not from the leak postThe website "co.cullman.al.us" represents Cullman County in Alabama. It serves as an online portal for county services, information, and resources. The site offers details about local government offices, departments, and officials, as well as public records, community events, and services for residents and businesses. It aims to enhance civic engagement and provide easy access to county-related information.
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

