Ncerio News blogCVE feed
What we measure across the estates we audit

Fort Smith Arkansas City Network Compromised in Ransomware Incident

Over 5.6 TB of data leaked from city infrastructure following ransomware attack
15 September 2026

The City of Fort Smith, Arkansas has been targeted by an interlock ransomware group. The incident involves a significant compromise of municipal systems and services. The sector context for the city is established at https://www.fortsmithar.gov/, where officials describe their commitment to resident-focused services.

According to ransomlook.io, the breach resulted in the exfiltration of more than 5.6 TB of confidential data. This volume includes critical infrastructure details regarding public safety and utility management. The leaked information covers the Police Station, Fire Department, and the Communications Center responsible for the 911 emergency dispatch service.

Data exposure also extends to the Water System, encompassing numerous water and sewer treatment plants. Information Systems supporting various city departments were accessed, including computer networks essential for daily operations. The scope of the leak includes databases and documents from these structures, providing comprehensive insight into city functions.

The compromised data contains sensitive personal information. Reports indicate that the Arkansas Crime Information Center and FBI Criminal Justice Information Service system details are available. This includes data on license plates, driver's licenses, and confidential law enforcement records. Personally identifiable information such as names, addresses, and phone numbers of residents was also exposed.

Further breaches include over 100,000 Social Security Numbers. Police station files with associated photos were leaked alongside software used by cyberpolice for phone data analysis. Reports and dumps from people's phones were also included in the release. The incident provides access to a complete database of 911 calls and incidents, highlighting the severity of the data exposure.

The source of this reporting is ransomlook.io. The original index page is located at http://dcwatuq6kzwj5i2sx7f2cx5hud2ryo3cnm6n6j2r6am57qskfqvdpeqd.onion/index.php?p=, detailing the specific files and scope of the leak. The city has faced criticism for negligent attitudes toward security, though this reporting focuses on the confirmed data exposure details provided by the source.

Source: City of Fort Smith Arkansas โ€” hit by interlock ransomware โ€” ransomlook.io
← all posts  ยท  CVE feed