The Pennsylvania Office of the Attorney General suffered a ransomware attack in August 2025, resulting in the theft of files containing personal and medical information, including Social Security numbers. The attack, claimed by the INC Ransom gang, disrupted the office’s operations by taking down its website, email, and phone systems, and forced staff to use alternative communication methods for nearly a month. The breach was discovered on August 9, and subsequent investigation confirmed that sensitive data was accessed and stolen, though officials have stated there is no evidence of misuse so far.
The ransomware group claimed to have stolen 5.7TB of data, and the office has notified affected individuals and the FBI. Security experts noted that the office had vulnerable Citrix NetScaler appliances exposed to the internet, which may have facilitated the breach. The incident caused significant disruption to Pennsylvania’s legal system, including delays in criminal and civil cases, but the office refused to pay the ransom demanded by the attackers.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
On 2025-11-17, Pennsylvania's Office of the Attorney General confirmed that the August ransomware incident involved unauthorized access and theft of files containing personal and medical information, including names and Social Security numbers. Officials said there was no evidence at the time that the stolen data had been misused.
On 2025-09-20, the INC Ransom group claimed responsibility for the attack, alleging it stole 5.7TB of data from the Pennsylvania OAG and asserting the compromise also provided access to an FBI internal network. Reporting also linked the incident to potentially exposed public-facing Citrix NetScaler appliances and possible exploitation of CVE-2025-5777, known as 'Citrix Bleed 2.'
In August 2025, the Pennsylvania Office of the Attorney General was hit by a ransomware attack that encrypted systems and caused widespread outages affecting its website, employee email, landline phones, and broader legal operations for nearly a month. Attorney General Dave Sunday later said the office refused to pay the ransom.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.