In mid-July 2024 the City of Columbus, Ohio was hit by ransomware attributed to Rhysida. The group listed the city and claimed 6.5TB of stolen data, offering it for sale before eventually publishing.
By November the city had notified approximately 500,000 people. Records reportedly included material relating to residents, employees and — through the city prosecutor’s systems — people who had interacted with the criminal justice process.
A City Is Not A Company
Nobody in Columbus chose to give the city their data, and nobody can decline. Residency is not a customer relationship: the records exist because the municipality provides services, employs people and prosecutes cases.
The corpus files that under concentration — the affected population had no say — but a municipality is the sharper version, because there is no competitor to move to and no contract to renegotiate.
The Volume Figure Is The Attacker’s
6.5TB came from the leak-site listing. The desk records it as a claim, as it does every attacker-originated volume.
What makes this file unusual is that the claim was independently checked — not by the city and not by a vendor, but by one person who downloaded the published set. That sequence is filed at 24-0829, and it is the most consequential thing about this incident.
Compiled from the city’s notification and contemporaneous reporting, listed below. Graded high: the 500,000 figure originates with the city’s own notification. The 6.5TB volume is an attacker claim from a leak-site listing and is labelled as such. Corrections: corrections@forensicpost.com.