On June 15, 2026, the Hood River County Sheriff’s Office website hoodriversheriff.com appeared on the leak site of the Safepay ransomware group. Public reporting indicates that internal files were exfiltrated during a ransomware attack on the Oregon agency responsible for patrol operations, criminal investigations, emergency communications, and search and rescue.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch hoodriversheriff.com
Get alerted the next time hoodriversheriff.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about hoodriversheriff.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Available reporting describes the incident as a ransomware deployment that resulted in data theft. The Safepay group published a post on its dark-web leak site listing hoodriversheriff.com and claiming to have obtained internal documents. The exact number of people affected remains unknown because neither the sheriff’s office nor the attackers have released a full victim count or detailed data inventory. The types of files taken have not been publicly itemized beyond the broad description of “internal files.” No evidence has surfaced that the attackers have begun selling the data or released samples.
Why This Matters for You and Your Family
When a local law enforcement agency loses control of internal records, the information often includes names, addresses, phone numbers, dates of birth, driver’s license details, and incident reports connected to ordinary residents. If your family has ever filed a police report, been involved in a traffic stop, applied for a permit, or lived in Hood River County, some of your personal information may now sit in an attacker’s hands. Once stolen, that data does not expire. It can be combined with other leaks to build a profile that makes identity theft, stalking, or targeted scams far easier. Children’s names linked to a parent’s report can also enter the pool, increasing long-term exposure for the entire household.
The Doxxing and Identity-Chain Implications
Ransomware leaks rarely stop at one dataset. Attackers or buyers frequently cross-reference the new material against earlier breaches, creating chains that link an old email address to a current phone number, gaming username, or home address. A single credential exposed in this incident can unlock accounts on other services if you have reused passwords. Public reporting shows these chains often lead to doxxing, where personal details are published on forums or sent directly to victims as part of extortion. Gaming accounts belonging to you or your children are especially vulnerable because they frequently share the same email or password patterns found in government or municipal breaches.