Chelan County data breach confirmed: what leaked and whether it affects you
If you were named in this filing, here’s what is being claimed, and what it would mean for you.
Chelan County confirmed that malware on its systems in May 2026 let someone access or copy personal information, including names, Social Security numbers, and government ID numbers. Public notices give no headcount; a filing with the Washington Attorney General says the event involves at least 500,001 Washington residents. There is no public list you can use to see whether your record was in the files.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
What’s already out there about you?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
In May 2026, malware reached Chelan County computer systems. The county says it noticed suspicious activity on or about 24 May, and that information was opened or copied without permission between 20 May and 24 May. A review of that data finished on 16 July and found personal information in it. The county told federal law enforcement early, then posted a public notice and filed with the Washington Attorney General on 11 August 2026.
The county says the information may include names; Social Security numbers (full or last four digits); driver's license or Washington ID numbers; bank or payment-card details; dates of birth; passport numbers; health-insurance or medical information; student or military ID numbers; and usernames, email addresses, and login credentials. The state's own listing of the incident describes the same mix. Public notices do not say how many people are involved. In the filing sent to the Attorney General, counsel for the county wrote that the event involves personal information relating to at least 500,001 Washington residents.
The story you heard is smaller than the file that left
Coverage has treated this as a local government tech problem: malware, an investigation, a notice on the county website. That framing is accurate and easy to scroll past if you do not live in Chelan County. It is also the part that matters least to you.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
What left the county is not “a malware incident.” It is a government file that can hold the exact combination other institutions use to accept someone as you: a name, a Social Security number, a date of birth, and a driver's license or state ID number. In some records there may also be card numbers, medical or insurance identifiers, a passport number, or the email and password for a county or other login. The county has not said which departments or which years of records were involved, and it has not said which of those fields sat in any one person's row. “May include” is not reassurance. It means they cannot tell you, from the outside, how complete your record was.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
The other thing official wording buries is scale. The pages written for the public say the number of people is unknown. The paper filed with the state uses a floor of 500,001 Washington residents. You should not treat this as someone else's local news because you do not live in Chelan County. Anyone in Washington whose information has ever sat in that county's systems has a reason to take the notice seriously. There is still no public roster, and no website can honestly look you up and tell you that you were or were not in this file.
The copy was taken in May. Most people heard in August. If anyone intends to misuse a record from this incident, they have already had time. Identity theft from this kind of mix also often shows up much later — a credit application, a tax return, a medical claim — not as a single dramatic week of fraud.
What to actually expect
- Do not wait for a letter before you decide this might touch you. The county used a website notice and statewide media. The public count is unknown. Plenty of people who are in the files may never get personal mail, and a letter would still not tell you which fields were yours.
- The likeliest harm is not an account takeover tomorrow. It is someone, months or years from now, opening credit, filing a tax return, or submitting an insurance or medical claim with your name, date of birth, and Social Security number.
- If an email address or a county-portal password was in the files, expect messages that look like Chelan County, a Washington agency, or a bank, written with just enough real detail to feel official. That is how leftover logins get used even when the rest of a file sits quiet.
- Card or bank numbers, if they were in your record, show up as ordinary bad charges. Medical or insurance identifiers show up as bills or claims you do not recognize. Those appear on statements, not in headlines.
What you can and cannot fix
If your Social Security number, driver's license or Washington ID number, date of birth, passport number, or medical or insurance identifiers were in the copied files, those facts are out. They cannot be pulled back. You cannot usefully change most of them. A password can be replaced. A Social Security number cannot. No one can unspread this copy, and no scan can give you a reliable yes or no on whether you were in it.
What actually helps, in order:
- Freeze your credit with Equifax, Experian, and TransUnion. A freeze is free. It is the step that stops a stranger from opening new credit in a name, date of birth, and Social Security number. Do it even if you never lived in Chelan County and even if no letter arrives. Thaw a bureau only when you yourself are applying for credit.
- Get an IRS Identity Protection PIN at IRS.gov. A fraudulent tax return needs the same three facts this incident put at risk. The PIN is what stops that return from being accepted in your name.
- Change passwords on email and on any county or state portal you use, and anywhere you reused those passwords. That does not put the stolen copy back; it stops the old login from working. After that, treat unexpected notes about Chelan County, refunds, or “verify your identity” as hostile until you go to the agency yourself by typing the address.
- Watch the bank, card, and insurance accounts you already have for charges or claims you did not make, and replace a card if you see them. That only helps for the financial and medical pieces, which were not in every record.
- Take your information off people-search sites. The stolen file may not include your current phone number, relatives, employer, or home address. Those sites add exactly that. A bare government record becomes much easier to use against you once it can be joined to a public listing that says where you live and who your family is. Unlike the breach copy, those listings can actually be removed.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Chelan County.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
- Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…
PayPal SSN Exposure Lasting Six Months — February 2026
A code change at PayPal allowed unauthorized access to Social Security Numbers and account details f…
Malaysia National Registration Department 22.5 Million — May 2022
A breach of Malaysia's National Registration Department exposed ~22.5 million citizen records, inclu…