The INC Ransom ransomware group claimed responsibility for a cyberattack on the Pennsylvania Office of the Attorney General, alleging the theft of 5.7 TB of data. Data samples purportedly stolen from the office were posted on INC's leak site, though the state has not confirmed the extent of the breach and has refused to pay the ransom. This incident is notable as the largest reported data theft from a U.S. government entity in 2025, according to security researchers. The attack highlights the growing threat posed by the INC Ransom group, which has targeted multiple high-profile organizations in recent months.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
In response to the incident, Pennsylvania's Office of the Attorney General said it would not pay ransom demands. The agency had not acknowledged the group's exfiltration claim at the time of reporting.
After the alleged intrusion, INC Ransom published multiple samples of purportedly stolen Pennsylvania OAG data on its leak site to support its extortion claim. The posting publicized the alleged scale of the theft.
INC Ransom claimed it compromised Pennsylvania's Office of the Attorney General in a cyberattack that occurred the month before the September 2025 reporting. The group alleged it stole 5.7 TB of data from the agency.
Within the 12 months preceding September 2025, INC Ransom publicly claimed several notable victims, including Ahold Delhaize USA, Dollar Tree, and two UK National Health Service hospitals. These claims reflected the group's continued activity and expanding victim list.
INC Ransom began operating more than two years before September 2025 and grew into a prolific ransomware-as-a-service group. Over the following years, it was linked to numerous victim claims across multiple sectors.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.