Skip to content

City of Columbus ransomware and data extortion incident

Summary

City of Columbus logo

A July 2024 cyberattack on the City of Columbus, Ohio, prompted network isolation and months of technology-service recovery, while attackers stole and published sensitive municipal data affecting 500,000 people. The city attributed the attack to Rhysida and said it prevented ransomware encryption; later disclosures included fire department health information for fewer than 1,000 people. City officials confirmed IT systems had been restored by July 2025.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Data extortion

    Threats to publish or sell stolen data without evidence of encryption.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data publication or leak

    Stolen, exposed, or otherwise compromised data was publicly released, posted, distributed, or offered for download.

  • Backup compromise

    Backup data or backup systems were accessed, encrypted, deleted, altered, disabled, or otherwise compromised.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internet access disruption

    The organization lost or materially restricted internet connectivity.

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

Extortion indicators

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Countdown or payment deadline

    The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.

Incident narrative

Analyst assessment

The City of Columbus, Ohio, detected a cyberattack on July 18, 2024, and severed internet connectivity to contain it, interrupting resident-facing technology services and internal operations. The city attributed the attack to Rhysida and said it prevented ransomware encryption, but attackers stole and published sensitive information. The city notified 500,000 people of potential exposure, according to BleepingComputer’s coverage of its breach filing. High confidence in the incident and attribution rests on city disclosures, the matching Rhysida claim and independent reporting; preventing encryption did not prevent disruption or data theft.

In its July 29 statement, the city corrected its initial explanation of access: investigators identified an internet website download rather than an email link. The city engaged the FBI, the Department of Homeland Security and outside cybersecurity experts. Rhysida’s July 31 victim claim alleged theft of 6.5 terabytes, including employee credentials, databases and emergency-service records. The Record reported that the group offered the data for 30 bitcoin and imposed a one-week deadline. The claimed volume and individual contents of that listing are not independently established in full.

Operational significance

The city’s July 19 outage post described disruption to internet-dependent services while 911 and 311 remained operational. Its July 22 cyber disclosure explicitly connected resident-facing outages to protective disconnection and also said payroll continued. External email was operating on city devices inside city buildings by July 29. These statements do not establish a citywide emergency-call outage, suspended payroll or a shutdown of every municipal service.

Recovery continued for months. The mayor’s Oct. 4 update reported that all critical IT systems were restored, but only 72% of 441 technology systems were fully restored and another 5% partially restored. The city’s 2024 financial report states that more than $7.3 million had been allocated by Dec. 31 for investigation, remediation, identity protection, legal counsel and security upgrades. That allocation is not a final loss estimate.

Data exposure extended across different municipal functions. The City Auditor’s September notice confirmed theft and publication of an unencrypted General Ledger backup containing 1999-2015 transactions; some vendors had used Social Security numbers as tax identifiers. The auditor said current income-tax, accounting and payroll systems were separate and had not been compromised. The Oct. 7 notification letter listed potentially affected names, dates of birth, addresses, bank account details, driver’s licenses, Social Security numbers and other information about interactions with the city. The 500,000-person total includes affected individuals, rather than establishing that every city resident or every listed data category was exposed.

On Feb. 3, 2025, the city disclosed that fewer than 1,000 people had protected health information in an affected Division of Fire dispatch database. The records could contain identity details and brief emergency medical service notes, with a small number of Social Security numbers. The city identified the health information on Dec. 12, 2024; it reported no evidence that the separate encrypted electronic medical record system was compromised. This was a later finding about the July attack, not a separate fire department intrusion.

Confidence and uncertainty

Cyber involvement, material service disruption, data theft and publication are established with high confidence by multiple city disclosures. Rhysida attribution is strongly supported by the city’s explicit Oct. 4 attribution and the matching victim claim. Ransomware-related extortion is confirmed, while successful encryption of city systems is not supported: the city expressly said it stopped encryption. The city’s corrected access account identifies a website download, and its subsequent notices establish that personal information was compromised.

July 18 is the supported detection and operational-start date; July 19 is the earliest verified public outage acknowledgment, and July 22 is the earliest verified cyber-specific disclosure. The actual intrusion may have begun earlier. Oct. 4 is the latest precisely dated continuing service-impact observation in the reviewed official updates; WOSU’s July 18, 2025 retrospective reports that some systems were not fully operational until 2025, without identifying the completion date.

Analytic gaps

The public record does not establish the exact initial intrusion date, full technical attack chain, final count of all exposed records, or the precise day every affected system returned to normal. Alleged stolen-data volumes should not be treated as audited totals. Exposure of health information does not establish compromise of the separate treatment-record system, and individual allegations of identity fraud do not establish that every later fraud event resulted from this attack.

Subsequent legal proceedings

An Ohio appeals court decision on Sept. 24, 2026, reversed the dismissal of consolidated complaints arising from the July 2024 attack and sent the cases back for further proceedings. The court assessed the allegations under the standard for a motion to dismiss; its decision did not establish that the city was negligent or determine damages. The litigation does not indicate renewed service disruption.

Current status

Operationally resolved. City spokeswoman Jennifer Fening confirmed that city IT systems had been restored in WOSU’s July 14, 2025 report. The report also described a $23 million security investment; continuing litigation, forensic review and security improvements are separate from continuing service disruption. The evidence supports restoration by that date, but not an exact completion date.

Threat actor and claim

Listed as: City of Columbus, OhioSource: ransomware.livePublished: Discovered:

Claim details

Rhysida listed City of Columbus, Ohio, alleging theft of 6.5 terabytes, including databases, employee credentials and emergency-service information. It offered the data for 30 bitcoin with a one-week deadline, according to The Record’s Aug. 1 report. Ransomware.live independently records the same victim and domain. The city later confirmed data theft, publication and Rhysida involvement in its Oct. 4 update. The alleged 6.5-terabyte total and full contents remain unverified.

Organizations involved

Impacted location

  • Columbus, Ohio

    Physical city anchor of the affected municipal government. City Hall at 90 West Broad Street documents the primary place; public evidence does not establish building-specific damage.

    Columbus municipal jurisdiction is the affected city government’s service-area overlay. It does not assert every city service or resident was affected. https://www.columbus.gov/Government

Sources

Network issue affecting City of Columbus services

The city reported an internet-dependent service disruption and said 911 and 311 remained operational.

City of Columbus Addressing Cybersecurity Incident

The city disclosed a cybersecurity incident detected July 18 and resident-facing outages caused by protective internet disconnection.

Columbus Thwarted Ransomware Encryption of its IT Infrastructure

The city said it thwarted encryption, identified access through a website download rather than an email link, and restored external email on city devices inside city buildings.

City Auditor notice of data breach and FAQs

An unencrypted General Ledger backup was stolen and posted online; historical records included some vendors’ Social Security numbers.

Cybersecurity Update-October 4, 2024

All critical IT systems were restored, while 72% of 441 systems were fully restored and 5% partly restored.

Notice of Data Breach — City of Columbus resident notification

The notice lists potentially involved identity, contact, banking and interaction information after unauthorized access and dark-web publication.

City of Columbus: Data of 500,000 stolen in July ransomware attack

The city notified 500,000 individuals that attackers stole and published personal and financial information.

Columbus Identifies Protected Health Information from Cyberattack

Fewer than 1,000 people had health information in an affected fire dispatch database; no evidence of compromise of the separate encrypted treatment-record system.

Doe v. Columbus, 2026-Ohio-3743 (Ohio 10th District Court of Appeals)

The court reversed dismissal of consolidated complaints arising from the July 2024 City of Columbus cyberattack and remanded for further proceedings. The opinion assumes pleaded allegations for the motion; it does not adjudicate negligence or damages.

City of Columbus Popular Annual Financial Report 2024

The report describes city governance and services and more than $7.3 million in incident-response allocations by Dec. 31, 2024.

City of Columbus, Ohio — Rhysida victim listing

The tracker records a Rhysida victim listing naming City of Columbus, Ohio, with domain columbus.gov, discovered July 31, 2024.

Government — City of Columbus, Ohio

The official directory documents municipal government functions, City Council, departments and City Hall at 90 West Broad Street.

Ohio County Profiles — Franklin County, 2025 Edition

Franklin County’s county seat is Columbus; the profile identifies its municipal, population and land-area context.

See something that needs correction?

Signed-in members can report an error, update, or missing source.