Ransomware victim disclosure
← All victimsloraincountyauditor.gov
Claimed by Global · listed 1 year ago
Status timeline
- ListedJul 14, 2025
- Data leakeddate unknown
At a glance
- Group
- Global
- Status
- Data leaked
- Country
- United States
- Sector
- Public Sector
- Listed on leak site
- Jul 14, 2025
About the victim
AI dossier — public-source company profileLorain County Auditor's Office in Ohio serves as the chief financial officer and property tax assessor for Lorain County. The office manages county finances, processes payroll for over 2,000 county employees, maintains property appraisals, distributes tax revenues to municipalities and school districts, and oversees licensing and weights/measures compliance.
- Industry
- Public Sector - County Government / Tax Assessment
- Address
- 226 Middle Ave., Room 200, Elyria, OH 44035-5641
- Founded
- 1824
Attack summary
Severity: high — Confirmed exfiltration of sensitive financial and banking data from a public sector entity managing county finances and serving 312,964 residents. Exposure of bank accounts and payroll systems represents significant operational and financial risk to county government.The ransomware group claims to have exfiltrated private information including bank accounts and related data from the county auditor's systems. No details on encryption or operational disruption are provided in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Bank account information
- Financial records
- Property tax data
- Payroll information
- Personal/private information
What the group claims
Lots of private information. Bank accounts and more.
Sources
- Victim siteloraincountyauditor.gov
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

