Skip to content

Lynx

Key facts

Claimed incidents
1
Public claims
1

Incident claim

Milton ransomware incident disrupts utility billing

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

A Lynx ransomware leak-site listing published Jan. 5, 2026, identifies miltonfl.org, the City of Milton’s official domain. The date is about 10 days after Milton later said it detected suspicious activity consistent with ransomware on Dec. 26, 2025, and nearly six months before the city publicly acknowledged the incident in June.

The listing contains a significant mismatch: while the claimed victim URL is the city’s domain, the attacker-provided description refers to MILTON-FL.RESTAURANTS800.COM, a restaurant directory unrelated to municipal government. One plausible explanation is that the description was generated or summarized by an automated system, possibly a large language model, and published without human review. Copied text, faulty metadata extraction or another leak-site editorial error are also possible.

There is still medium confidence that the Lynx post refers to the same incident later disclosed by Milton because the official city domain is named, the dates closely align and the claim predates the city’s disclosure by about six months. However, Milton has not confirmed Lynx as the attacker, and DysruptionHub did not find sample files or a public tranche of allegedly stolen city data attached to the listing.

The city later said investigators found no indication city information was accessed, acquired, copied, leaked, posted publicly or otherwise taken. The Lynx entry should therefore be treated as claim-level evidence that likely corresponds to Milton’s incident, not as confirmation of the threat actor or data theft.

Impacted organizations

Impacted locations