Union County, Ohio, experienced a significant ransomware attack in May 2025 that resulted in the compromise of sensitive personal data belonging to 45,487 individuals, including both residents and county employees. The attack was detected on May 18, 2025, after cybercriminals had maintained unauthorized access to the county’s network from May 6 to May 18. During this period, the attackers exfiltrated a wide range of sensitive information, such as names, Social Security numbers, financial account details, driver’s license numbers, medical information, fingerprint data, and passport numbers. Upon discovery of the ransomware, Union County officials immediately launched an investigation, enlisting the help of nationally recognized third-party cybersecurity and data forensics consultants to secure their network and determine the scope of the breach. Federal law enforcement agencies were also notified as part of the county’s incident response. By August 25, 2025, the county had completed its review of the breach and began sending notification letters to all affected individuals, outlining the types of data compromised and the steps being taken in response. As of late September 2025, no known ransomware group had claimed responsibility for the attack, and the specific threat actor remains unidentified. The breach notification letters emphasized the breadth of the data stolen, highlighting the potential risks for identity theft and financial fraud among those affected. Union County, with a population of over 75,000 and recognized as one of Ohio’s fastest-growing regions, faced significant operational and reputational challenges as a result of the incident. The attack on Union County is part of a broader trend of ransomware campaigns targeting state, county, and city governments across the United States in 2025. Other recent incidents have included attacks on North Carolina’s Waxhaw town, where the Qilin ransomware gang exfiltrated over 600 GB of data, as well as separate breaches affecting Ohio’s Lorain County and the Maryland state government. The Union County incident underscores the persistent threat posed by ransomware actors to local government entities and the critical importance of robust cybersecurity measures, timely incident response, and transparent communication with affected stakeholders. The county’s response included not only technical remediation but also public disclosure and cooperation with law enforcement, reflecting best practices in breach management. The full impact of the breach, including any potential misuse of the stolen data, remains to be seen as investigations continue. Union County’s experience serves as a cautionary example for other local governments regarding the risks of ransomware and the need for comprehensive data protection strategies.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Union County, Ohio reported a ransomware attack that impacted more than 45,000 individuals. The incident was publicly disclosed in late September 2025 and described as affecting county systems and residents' data.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.