Ransomware victim disclosure
← All victimsThe City of Hesperia, CA
Claimed by INC Ransom · listed 3 months ago
Status timeline
- ListedMar 4, 2026
- Data leakeddate unknown
At a glance
- Group
- INC Ransom
- Status
- Data leaked
- Country
- United States
- Sector
- Public Sector
- Listed on leak site
- Mar 4, 2026
About the victim
AI dossier — public-source company profileThe City of Hesperia is a municipal government entity located in San Bernardino County, California, incorporated in 1988. It provides public services including administration, public works, planning, and law enforcement coordination to approximately 100,000 residents in the High Desert region. As a local government body, it maintains a wide range of sensitive records relating to residents, employees, contracts, and financial transactions.
- Industry
- Municipal Government
- Address
- 9700 Seventh Avenue, Hesperia, CA 92345, United States
- Employees
- 201-500
- Founded
- 1988
Attack summary
Severity: critical — Confirmed exfiltration and publication of regulated PII at scale (employees and government officials), financial records, and sensitive government contracts/NDAs from a municipal government entity; data_published status indicates the data has already been released publicly.INC Ransom claims to have exfiltrated files containing sensitive government data including state secrets, NDAs, contracts with public and private entities, personal data of employees and government officials, and financial records including transactions, payments, and tax documents; the disclosure status is listed as data_published indicating the stolen data has been released.
Data the group says was taken
AI dossier — extracted from the leak post- State secrets / classified government documents
- Non-disclosure agreements
- Contracts with private and public companies
- Employee personal data (PII)
- Government officials' personal data (PII)
- Transaction records
- Payment documents
- Tax documents
What the group claims
Access was gained to files containing state secrets, non-disclosure agreements, contracts with private and public companies, as well as personal data of employees and government officials. Transactions, payment, and tax documents were also obtained.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

