City of McMinnville Data Breach Exposes Tax Returns, Passwords, and Police Records

Published: 1 October 2026
Other Commercial data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

The City of McMinnville confirmed that a ransomware attack, claimed by the group RansomHouse, exposed tax returns, passwords, bank information, HR records, and confidential police files, including witness statements. The breach was discovered after a cybersecurity researcher found the data posted on the dark web in August 2026. Affected individuals should immediately check their credit reports and consider a credit freeze.

CompanyCity of McMinnville
IndustryOther Commercial
Data Types ExposedTax Returns, Passwords, Bank Account Information, Human Resources Records, Confidential Police Records, Witness Interview Statements
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedCalifornia Attorney General, Vermont Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the City of McMinnville Data Breach?

The City of McMinnville has confirmed a serious data breach that exposed a wide range of sensitive municipal records. The incident came to light after a cybersecurity researcher found city files circulating openly on the dark web. According to his account, it took only a few clicks to locate deeply personal and confidential material that should never have been public.

The breach discovery date has not been publicly disclosed. However, the stolen data was leaked online in August 2026 by a ransomware group known as RansomHouse. As a result, files tied to city operations, residents, and employees became accessible to anyone who knew where to look.

The city issued a formal notice about the incident on September 29, 2026. Because RansomHouse claimed responsibility for the attack, this breach appears to stem from a ransomware intrusion rather than a simple technical error. Following discovery, the city appears to have launched a review of the exposed material and begun notifying people whose information was affected. The full scope of the forensic investigation has not been detailed publicly.

Who was affected?

The breach may affect a broad mix of people connected to McMinnville city government. This includes residents whose tax records were handled by the city, current and former city employees, and individuals who interacted with the police department. In addition, witnesses who gave statements to police may be impacted, since confidential interview records were reportedly among the exposed files.

The exact number of affected individuals has not been publicly disclosed. Because the leaked data reportedly includes human resources files, the breach may include both city staff and their dependents. Given that police records were involved, some witnesses or crime victims may also be affected, even if they never had direct dealings with city hall outside of a police matter.

What Information Was Potentially Exposed?

The scope of exposed information in this breach appears unusually broad for a municipal government incident. A cybersecurity specialist who reviewed the leaked files described finding records spanning nearly every function of city operations.

  • Tax returns
  • Passwords
  • Bank account information
  • Human resources records
  • Confidential police records
  • Witness interview statements

This combination of financial, employment, and law enforcement data creates serious identity theft risk. For example, tax returns often include Social Security numbers, income details, and dependent information that criminals can use to file fraudulent tax returns or open new credit accounts. Because passwords were also exposed, affected individuals face a heightened risk of account takeover if they reused login credentials elsewhere.

The presence of confidential police records adds another layer of concern. Witnesses whose identities were meant to stay protected could face safety risks if their information falls into the wrong hands. In addition, bank account details could enable direct financial fraud, including unauthorized withdrawals or fraudulent transfers. Because HR records often include dates of birth and employment history, affected employees may also face a higher risk of targeted phishing attempts.

What is the company doing?

The City of McMinnville posted a notice about the data privacy event on its official website on September 29, 2026. This notice appears to represent the city’s public acknowledgment of the breach following the online leak of its files. According to local news coverage, the city has been reaching out to people whose private details were stolen.

The city also filed formal notification with the California Attorney General and the Vermont Attorney General on September 29, 2026. These filings suggest the breach affected residents beyond Oregon’s borders. Specific details about remediation steps, such as network security upgrades or whether credit monitoring is being offered, have not been fully outlined in available public reporting.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Affected individuals should request copies of their credit reports from all three major credit bureaus. Reviewing these reports regularly can help catch new accounts or inquiries that you did not authorize. Because tax and financial records were involved in this breach, this step is especially important.

You can obtain a free credit report from each bureau through AnnualCreditReport.com. Checking your reports every few months, rather than just once, gives you a better chance of catching fraud early. If you notice anything unfamiliar, dispute it with the bureau immediately.

Consider a Fraud Alert or Credit Freeze

Given that tax returns and bank information were exposed, placing a fraud alert or credit freeze on your credit file is a smart precaution. A fraud alert requires lenders to verify your identity before issuing new credit. A credit freeze goes further by blocking most access to your credit file entirely.

Either option can help prevent someone from opening new accounts in your name. Because this breach involved financial and tax data, criminals could attempt identity theft using your Social Security number. Contacting each of the three credit bureaus directly is the fastest way to set up these protections.

Change Reused Passwords Immediately

Since passwords were part of the leaked data, affected individuals should change any passwords tied to city accounts right away. This is especially urgent if you reused that password on other websites or services. Attackers often test stolen credentials across multiple platforms, a tactic known as credential stuffing.

Using a unique, strong password for every account reduces this risk significantly. A password manager can help generate and store these credentials securely. In addition, enabling multi-factor authentication wherever possible adds another layer of protection against unauthorized access.

Stay Alert for Phishing and Scam Attempts

Because so much personal information was exposed, affected individuals should watch for suspicious emails, texts, or phone calls. Scammers often use details from breaches to make their messages appear legitimate. For instance, a scammer might reference your real tax information to convince you a message is genuine.

Never click links or share personal details in response to unsolicited messages. Instead, contact the organization directly using a verified phone number or website. If you are unsure whether a communication is legitimate, it is safer to simply delete it.

Consult a Data Breach Attorney

Given the scale and sensitivity of the exposed records, affected individuals may want to speak with a data breach attorney. An attorney can help determine whether you qualify for compensation or participation in a class action lawsuit. Many offer free initial consultations to evaluate your situation.

Because this breach involved highly sensitive categories like police records and financial data, legal options may be more substantial than in a typical breach. An attorney can also help you understand notification deadlines and your rights under state law. Taking this step early can help preserve your legal options.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

Official data breach notification from California Attorney General

View the public data breach notification listing from Vermont Attorney General

Related Data Breaches

Browse all recent data breaches →