Government entity · Public services and administration · County government · USA
County government in Michigan.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
On October 3, 2024, Wayne County, Michigan suffered a ransomware attack that disabled county websites and disrupted property-tax, court, and jail operations. In February 2025 the Interlock ransomware group claimed responsibility, saying it had exfiltrated roughly 7.7 TB across more than 130 SQL databases, including resident personal data, bank account details, and a large collection of confidential criminal-investigation files; the data was leaked around March 1, 2025. Confirmed circulating identifiers include Social Security numbers, emails, and phone numbers, with reporting also citing bank account and criminal-records exposure. The record reflects approximately 206,287 affected individuals (of ~1.75 million county residents).
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
206K records analyzed
Wayne County is the most populous county in Michigan (home to Detroit), serving roughly 1.75 million residents. Its government administers property tax, courts and criminal justice, vital records, health, and other public services, maintaining resident, employee, vendor, tax, property, court, and criminal-justice records across county systems.
County governments aggregate identity, address, tax, property, court, licensing, and public-service records tied to residents, employees, vendors, and administrative operations.
An October 3, 2024 ransomware attack disabled county websites and disrupted property-tax payments, case management, estate sales, inmate processing, and court scheduling. In February 2025 the Interlock ransomware group claimed responsibility, and the stolen data was leaked around March 1, 2025. The county worked to restore services and investigate.
The breach exposed a large volume of resident data, including Social Security numbers, bank account details, and confidential criminal-investigation and court records, creating identity-theft, financial-fraud, and privacy harms and raising unusual risks around exposure of criminal-justice information. The attack also disrupted essential public services for one of the nation's largest counties, eroding public trust.
• Identity theft and synthetic identity construction using SSN | • Financial fraud using exposed bank account details | • Exposure and misuse of confidential criminal-investigation and court records | • Government-services and benefits-fraud phishing | • SIM swap and vishing attacks where phone numbers are present
A government-linked breach: official identifiers and citizen records support identity fraud and credible authority-impersonation. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.
Motivation: Financial extortion
A ransomware and data-extortion operation active since around September 2024, impacting businesses and critical infrastructure across North America and Europe via a double-extortion model (encrypt plus steal).
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation