Desk live·
ForensicPost
Breaches/Accountability/File 24-0829

He Opened the Files, and the City Sued Him

A researcher downloaded the published data, showed reporters it was neither encrypted nor corrupted, and was met with a lawsuit and a restraining order.

Constructed geometry · not a chart of case data
JurisdictionUSAColumbus, Ohiothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetCity of Columbus
ActorRhysida
D. Kennedy14 min readConfidence: high3 sources reviewed

Connor Goodwolf — legal name David Leroy Ross — retrieved the data Rhysida had published and showed samples to local reporters. It contained readable personal information about people in Columbus, including material from prosecutorial systems.

The city sued him, seeking damages in excess of $25,000, and obtained a temporary restraining order from a Franklin County judge barring him from accessing, downloading or disseminating the stolen files.

The sequenceContemporaneous reporting
TimeEventEvidence
July 2024Ransomware; Rhysida claims 6.5TBLeak-site listing — 24-0718
August 2024Mayor says data is encrypted or corrupted, unusablePublic statement — 24-0813
August 2024Researcher shows media the data is readableReported
Late August 2024City sues; restraining order grantedCourt filing, reported
LaterCity moves to dismiss; order liftedReported — 24-1024

What The Restraining Order Actually Restrained

Not the data. Rhysida had already published it and the copies were beyond any court’s reach. What was restrained was one person’s ability to look at it and describe what he found.

The practical effect was to leave the mayor’s characterisation standing as the only account, while the person who could contradict it was under order not to.

The City’s Position Was Not Frivolous

Circulating stolen personal data does harm the people in it, and a municipality has an interest in limiting further spread. Reporting indicated the researcher shared samples with journalists rather than publishing the set, but the distinction is finer in law than it is in a headline.

This desk records that because the easy version of this story — city silences whistleblower — is available and incomplete. Both things are true: the concern about spreading the data was legitimate, and the effect of the action was to suppress the correction of a false public statement.

Who Is Left To Verify A Breach

This corpus grades attacker claims low because attackers benefit from large numbers. It grades organisation statements higher because they carry legal consequence. Both instruments failed here: the attacker’s 6.5TB was unverified and the city’s reassurance was wrong.

The only party that established anything was an individual who downloaded the files. Independent verification of a breach is done almost entirely by people with no institutional protection, and this is the case where one of them was sued for it.

How we reported this

Compiled from contemporaneous reporting of the litigation and the restraining order, listed below. Graded high: the filing, the order and the researcher’s demonstration were all publicly reported at the time. This desk has not reviewed the court documents. The researcher is named because he identified himself publicly and is not accused of a crime; no finding was made against him and the action was later dismissed — see 24-1024. Corrections: corrections@forensicpost.com.

Sources
  1. Researcher sued for sharing data stolen by ransomware with mediaBleepingComputer
  2. City sues security researcher after revelations about ransomware attackFreedom of the Press Foundation
  3. He proved the Columbus data leak hurts the publicNBC4 Columbus
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary